Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#71117 - [pass] use signed tag
Attached to Project:
Community Packages
Opened by T.J. Townsend (blakkheim) - Thursday, 03 June 2021, 21:27 GMT
Last edited by Brett Cornwall (ainola) - Friday, 29 July 2022, 17:30 GMT
Opened by T.J. Townsend (blakkheim) - Thursday, 03 June 2021, 21:27 GMT
Last edited by Brett Cornwall (ainola) - Friday, 29 July 2022, 17:30 GMT
|
DetailsDescription:
Attached diff switches the pass package to use a PGP-signed git tag for authenticity. |
This task depends upon
Closed by Brett Cornwall (ainola)
Friday, 29 July 2022, 17:30 GMT
Reason for closing: Implemented
Additional comments about closing: GPG signed tags are now set up in the PKGBUILD. Thanks for reporting!
Friday, 29 July 2022, 17:30 GMT
Reason for closing: Implemented
Additional comments about closing: GPG signed tags are now set up in the PKGBUILD. Thanks for reporting!
pass.diff
The key has an expiration date of 2022-02-11, so it should be good to go! I know you're using release tarballs now instead of git but it might be worth considering a switch back to git for that verification.