Re: Verify upstream PGP signed sha256sums file

2023-09-02 Thread Ben Westover
Hi, On 9/1/23 08:10, Yadd wrote: > there is an issue opened for that (#1014333), contributions welcome ! Ah, thanks for the info! -- Ben Westover OpenPGP_signature.asc Description: PGP signature

Re: Verify upstream PGP signed sha256sums file

2023-08-31 Thread Yadd
On 9/1/23 08:10, Ben Westover wrote: Hello, I add PGP verification to my debian/watch files wherever possible so that if upstream has a signature on their tarball, it can be verified. I've seen a few projects now that choose to include a clearsigned file that contains the sha256sums of all

Verify upstream PGP signed sha256sums file

2023-08-31 Thread Ben Westover
Hello, I add PGP verification to my debian/watch files wherever possible so that if upstream has a signature on their tarball, it can be verified. I've seen a few projects now that choose to include a clearsigned file that contains the sha256sums of all their tarballs and binaries instead of