Re: [Rpm-maint] [rpm-software-management/rpm] Installation / verification should not pass if the (sub)key(s) has been revoked or expired (#1598)

2021-07-05 Thread Stephan
There is another issue that is not covered by revocation at all. A software package is obsolete as soon as a new version of the package is signed, especially if there is a known vulnerability in the old version. However, the signature of the vulnerable version obviously stays valid. If the secur

Re: [Rpm-maint] [rpm-software-management/rpm] Can't use `--define "_gpg_name Foo"` any more (#153)

2018-07-10 Thread Stephan
Agreed with jsumners > As a user, those details don't matter to me Confirmed with pmatilai: > minimally supported > wont handle this case Even the --macros is not passed properly to rpmsign, when called from rpmbuild ... At least, documentation is updated, somewhere, to provide info on that top

Re: [Rpm-maint] [rpm-software-management/rpm] RFE: rpm should permit a means to add arbitrary tags to packages (#413)

2018-07-12 Thread Stephan
Would it be possible to query those tags, via RPM query itself ? Thinking of something like rpm -qp --qf '%{applicationspecifictag}\n' ./application.rpm -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/r