[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#982562: general: Storing upstream signatures next to upstream tarballs is problematic



Hi,

Am 11.02.21 um 21:59 schrieb Raphaël Hertzog:

> [1] For details it happened in dbus-glib:
> https://snapshot.debian.org/package/dbus-glib/0.110-2/ -> it has .asc file
> https://snapshot.debian.org/package/dbus-glib/0.110-3/ -> no .asc
> https://snapshot.debian.org/package/dbus-glib/0.110-4/ -> no .asc
> https://snapshot.debian.org/package/dbus-glib/0.110-5/ -> it has a
> different .asc file
>
Why should anything else than -1 have a .asc file anyways in the upload?

That's .orig.tar.xz (or whatever compression) and the accompanying
.orig.tar.xz.asc.

Since -2 etc don't upload the .orig again there's no need to upload the
signature of the .orig again.


(And then there ia slso the problem that subcomponent tarballs can't get
their .ascs when they need to be repa ckaged to fill dpkgs needs. So
stuff like LO only gets the .asc for the "core" tarball but not for
helpcontent2 and translations, which would have .asc files otherwise)

Regards,


Rene


Reply to: