dehydrated-0.7.2.tar.gz.asc is not a detached signature #640

Closed
opened 2025-12-29 01:28:07 +01:00 by adam · 2 comments
Owner

Originally created by @andreaso on GitHub (May 18, 2025).

Historically dehydrated-0.7.1.tar.gz.asc, dehydrated-0.7.0.tar.gz.asc, dehydrated-0.6.5.tar.gz.asc, etc have all been detached signatures to their corresponding release tarball.

dehydrated-0.7.2.tar.gz.asc on the other hand is a full complete self-contained thing, containing both the original file content as well as the signature.

While not necessarily wrong it is a bit unusual, so I figured that I might as well mention it.

Originally created by @andreaso on GitHub (May 18, 2025). Historically _dehydrated-0.7.1.tar.gz.asc_, _dehydrated-0.7.0.tar.gz.asc_, _dehydrated-0.6.5.tar.gz.asc_, etc have all been detached signatures to their corresponding release tarball. _dehydrated-0.7.2.tar.gz.asc_ on the other hand is a full complete self-contained thing, containing both the original file content as well as the signature. While not necessarily wrong it is a bit unusual, so I figured that I might as well mention it.
adam closed this issue 2025-12-29 01:28:07 +01:00
Author
Owner

@bleve commented on GitHub (May 18, 2025):

This is blocking problem for doing rpm packaging of dehydrated because gpgverify requires detached signature for verification.

@bleve commented on GitHub (May 18, 2025): This is blocking problem for doing rpm packaging of dehydrated because gpgverify requires detached signature for verification.
Author
Owner

@lukas2511 commented on GitHub (May 18, 2025):

Whoopsie... sorry for that, I've swapped the file. Thanks for reporting.

@lukas2511 commented on GitHub (May 18, 2025): Whoopsie... sorry for that, I've swapped the file. Thanks for reporting.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/dehydrated#640