Bug#852801: devscripts: Please add support for signing/signed .buildinfo

Guillem Jover guillem at debian.org
Fri Jan 27 13:08:16 UTC 2017

Source: devscripts
Source-Version: 2.17.0
Severity: important
X-Debbugs-Cc: reproducible-builds at lists.alioth.debian.org


The .buildinfo files were supposed to be signed, but dpkg-buildpackage
didn't do that until dpkg 1.18.19. Even then, when we sign sources and
those get referenced in the .buildinfo file, their checksums will not
match as they have been changed.

I've prepared a patch for dscverify to test the new dpkg, but debsign
is still pending. Patch attached, please review.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-dscverify-Add-support-for-.buildinfo-files.patch
Type: text/x-diff
Size: 3667 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/reproducible-builds/attachments/20170127/a0c478cb/attachment.patch>

More information about the Reproducible-builds mailing list