[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Linitian orig-tarball-missing-upstream-signature

On Mon, Jul 31, 2017 at 4:24 AM, Ole Streicher wrote:

> is not really helpful to me; at least I did not find a mention in the
> Debian policy that the signature should be included in the .changes
> file. Also, it seems that the standard (pdebuild) toolchain does not
> include it by default.

Policy documents current practice rather than describing what
practices should be taken, so I think that we will only get this in
policy once it is more common.

The standard toolchain here is uscan, not pdebuild, and there is a bug
asking placing the signatures in the correct place open already, it
just needs someone to do the work:


> What is the preferred way to included the upstream signature?

Before building the source package, place the upstream signature file
alongside the orig.tar, with the same name, but with .asc appended to
it. When that is done, then dpkg-source will include the signature in
the .dsc and it will be copied to the .changes file too.

> Was there some discussion about this in debian-devel that I missed?

I guess the only discussion was in the lintian bug report:




Reply to: