Why, may I ask, are we validating a signature that isn't from upstream? This seems (and most likely is) wrong.
The point of signatures is to validate the upstream packager's sigs, not the AUR maintainer's.
I would advise users of this PKGBUILD to remove the signature from the sources and sums arrays and just not bother.
Search Criteria
Package Details: debianutils 5.20-1
Package Actions
Git Clone URL: | https://aur.archlinux.org/debianutils.git (read-only, click to copy) |
---|---|
Package Base: | debianutils |
Description: | Miscellaneous utilities specific to Debian |
Upstream URL: | https://tracker.debian.org/pkg/debianutils |
Licenses: | GPL |
Submitter: | sanerb |
Maintainer: | javmorin (sanerb) |
Last Packager: | javmorin |
Votes: | 7 |
Popularity: | 0.000000 |
First Submitted: | 2015-08-25 00:00 (UTC) |
Last Updated: | 2024-09-18 18:38 (UTC) |
Required by (3)
Sources (1)
Latest Comments
« First ‹ Previous 1 2 3
markzz commented on 2016-09-04 22:30 (UTC) (edited on 2016-09-04 22:30 (UTC) by markzz)
sanerb commented on 2016-06-26 04:31 (UTC) (edited on 2017-09-01 22:44 (UTC) by sanerb)
Please note the following additions:
# Bug reports can be filed at https://bugs.square-r00t.net/index.php?project=3
# News updates for packages can be followed at https://devblog.square-r00t.net
(If you want an RSS-feed only pertaining to my AUR packages, you can subscribe to https://devblog.square-r00t.net/rss/?category=aur in your favourite RSS reader.)
Note that you should still use the AUR web interface for flagging packages as out-of-date if a new version is released; the aforementioned bug tracker is to aid in issues with building/packaging/the PKGBUILD formats/etc. specifically.
GPG signature "errors" are explained here:
https://devblog.square-r00t.net/articles/a-note-on-using-gpg-signatures-in-pkgbuilds
Please read; it's not a bug.
Thanks!
sanerb commented on 2016-06-03 19:26 (UTC)
you need to either ignore pgp verification (makepkg --skippgpcheck) or import my key (which can be found at https://square-r00t.net/gpg/bin/personal.gpg - fingerprint is in my AUR profile, i'm also on keybase.io and other keyservers).
see https://wiki.archlinux.org/index.php/makepkg#Signature_checking
project0 commented on 2016-05-23 13:30 (UTC)
Build fails on invalid PGP-Signature.
Pinned Comments
sanerb commented on 2016-06-26 04:31 (UTC) (edited on 2017-09-01 22:44 (UTC) by sanerb)