Utility for secure communication and data storage
Go to file
Todd Zullinger 9308d65403 verify upstream signatures in %prep, unless bootstrapping
Per the guidelines¹, verify upstream signatures, unless we are in
bootstrap mode.

The fingerprints of the keys contained in signature_key.asc were checked
against the upstream page (https://gnupg.org/signature_key.html).  One
downside is that we are unable to verify signatures made with only the
brainpool key.  The hope is that such releases are relatively rare and
the benefit of automated signature verification outweighs the hassle of
handling such releases.  For these releases, set skip_verify to 1, as
we've done here.  Afterward, reset it to 0.

¹ https://docs.fedoraproject.org/en-US/packaging-guidelines/#_source_file_verification
2022-10-17 14:30:16 -04:00
.gitignore add forgotten sources 2022-07-12 12:27:08 +02:00
gnupg2-yk5.patch Fix Yubikey 5 detection 2022-08-01 12:13:43 +02:00
gnupg2.spec verify upstream signatures in %prep, unless bootstrapping 2022-10-17 14:30:16 -04:00
gnupg-2.1.1-fips-algo.patch gnupg2-2.3.1-1 2021-05-01 20:19:00 +02:00
gnupg-2.1.10-secmem.patch upgrade to 2.1.10 2015-12-07 16:47:21 +01:00
gnupg-2.2.18-gpg-accept-subkeys-with-a-good-revocation-but-no-self-sig.patch Introduce Debian patches for #1787708 2020-01-04 14:17:15 +01:00
gnupg-2.2.18-gpg-allow-import-of-previously-known-keys-even-without-UI.patch gnupg2-2.3.1-1 2021-05-01 20:19:00 +02:00
gnupg-2.2.18-tests-add-test-cases-for-import-without-uid.patch Introduce Debian patches for #1787708 2020-01-04 14:17:15 +01:00
gnupg-2.2.20-file-is-digest.patch Fix file-is-digest patch (#2022904) 2021-11-15 09:36:26 +01:00
gnupg-2.2.21-coverity.patch gnupg-2.3.4-1 2021-12-21 11:57:55 +01:00
gnupg-2.2.23-large-rsa.patch upgrade to 2.2.23 2020-09-04 14:06:31 +02:00
signature_key.asc verify upstream signatures in %prep, unless bootstrapping 2022-10-17 14:30:16 -04:00
sources add forgotten sources 2022-07-12 12:27:08 +02:00