[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#944707: lintian: check for missing and unsigned .buildinfo files



Dear Vagrant,

> Maybe lintian isn't the right place for this (yet), but happy to have
> started and to continue the conversation.

Agreed and just to underline again I am — of course — very much +1
on the case for .buildinfo files, but I would likely agree with you that
Lintian is not the best place for this, at least right now.

For starters, if Lintian complained about unsigned .buildinfo files it
would seem sensible to warn about unsigned .changes "first", unless we
wanted to specifically check the rather niche-sounding case of a
signed .changes but an unsigned .buildinfo; technically possible with
the right arguments to dpkg-buildpackage, but it feels a bit unlikely.

(Practically-speaking, if a user/workflow was using very old tooling
it is unlikely they would be using a [future] version of Lintian that
would have this check too. And does lintian.debian.org even have
access to buildinfo files...? These are lesser and somewhat
rhethorical questions that do not really need an answer.)

Anyway, thanksindeed for starting this conversation in terms of
finding ways of getting more .buildinfo files into the archive. :)


Best wishes,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org 🍥 chris-lamb.co.uk
       `-


Reply to: