Bug#874667: uscan: please remove upstream signature when repacking tarballs
Guido Günther
agx at sigxcpu.org
Fri Sep 8 14:38:55 UTC 2017
Package: devscripts
Version: 2.17.9
Severity: wishlist
File: /usr/bin/uscan
Hi,
the upstream signture will no longer verify successfully if uscan
repacks the tarball using the information from debian/copyright. In this
case uscan should remove the signature to make sure no other tools pick
it up by accident and fail signature verification later on.
Cheers,
-- Guido
-- Package-specific info:
--- /etc/devscripts.conf ---
--- ~/.devscripts ---
DEBSIGN_KEYID=0xB999CDB58C8DDBD2
-- System Information:
Debian Release: buster/sid
APT prefers testing
APT policy: (990, 'testing'), (500, 'unstable-debug'), (500, 'testing-debug'), (500, 'oldoldstable'), (500, 'unstable'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 4.12.0-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
Versions of packages devscripts depends on:
ii dpkg-dev 1.18.24
ii libc6 2.24-17
ii libfile-homedir-perl 1.00-1
ii perl 5.26.0-5
ii python3 3.5.3-3
Versions of packages devscripts recommends:
ii apt 1.5~rc1
ii at 3.1.20-3
ii curl 7.55.1-1
ii dctrl-tools 2.24-2+b1
ii debian-keyring 2017.08.28
ii dput-ng [dput] 1.15
ii dupload 2.9.0
ii equivs 2.1.0
ii fakeroot 1.22-1
ii file 1:5.32-1
ii gnupg 2.1.23-2
ii gnupg2 2.1.23-2
ii libdistro-info-perl 0.17
ii libdpkg-perl 1.18.24
ii libencode-locale-perl 1.05-1
ii libgit-wrapper-perl 0.047-1
ii liblist-compare-perl 0.53-1
ii liblwp-protocol-https-perl 6.07-2
ii libsoap-lite-perl 1.20-1
ii liburi-perl 1.72-1
ii libwww-perl 6.15-2
ii licensecheck 3.0.30-1
ii lintian 2.5.52
ii man-db 2.7.6.1-2
ii patch 2.7.5-1+b2
ii patchutils 0.3.4-2
ii python3-debian 0.1.30
ii python3-magic 1:5.32-1
ii python3-unidiff 0.5.4-1
ii sensible-utils 0.0.10
ii strace 4.15-2
ii unzip 6.0-21
ii wdiff 1.2.2-2
ii wget 1.19.1-4
ii xz-utils 5.2.2-1.3
Versions of packages devscripts suggests:
pn adequate <none>
ii autopkgtest 4.4
pn bls-standalone <none>
ii bsd-mailx [mailx] 8.1.2-0.20160123cvs-4
ii build-essential 12.3
pn check-all-the-things <none>
pn cvs-buildpackage <none>
pn devscripts-el <none>
pn diffoscope <none>
pn disorderfs <none>
pn dose-extra <none>
pn duck <none>
pn faketime <none>
ii gnuplot 5.0.7+dfsg1-1
ii gnuplot-x11 [gnuplot] 5.0.7+dfsg1-1
ii gpgv 2.1.23-2
pn how-can-i-help <none>
ii libauthen-sasl-perl 2.1600-1
ii libfile-desktopentry-perl 0.22-1
pn libnet-smtps-perl <none>
pn libterm-size-perl <none>
ii libtimedate-perl 2.3000-2
pn libyaml-syck-perl <none>
ii mozilla-devscripts 0.47
ii mutt 1.8.3+neomutt20170609-2+b1
ii openssh-client [ssh-client] 1:7.5p1-10
pn piuparts <none>
ii quilt 0.63-8.1
ii ratt 0.0~git20160202.0.a14e2ff-1+b2
pn reprotest <none>
pn svn-buildpackage <none>
ii w3m 0.5.3-34
-- no debconf information
More information about the devscripts-devel
mailing list