Format: 1.8 Date: Sat, 13 Feb 2016 11:32:58 +0100 Source: debsig-verify Binary: debsig-verify Architecture: armhf Version: 0.14 Distribution: xenial-proposed Urgency: low Maintainer: Launchpad Build Daemon Changed-By: Guillem Jover Description: debsig-verify - Debian package signature verification tool Changes: debsig-verify (0.14) unstable; urgency=low . * Assume at least C89 and POSIX.1-2001. * Fix man page formatting. * Add references to debsigs(1) and gpg(1) to the man page. * Add missing man page .TH fields. * Use https instead of git or http in URLs. * Add new test case covering key to name id mapping. * Switch to use more of libdpkg instead of ad-hoc code: - Use path_make_temp_template(). - Switch from popen() to subproc_fork() and execlp(), to avoid shell invocation and unsafe argument passing. - Use the command module to invoke GnuPG instead of execlp(). * Do not use an absolute pathname to the GnuPG program. * Make the GnuPG program configurable through the DEBSIG_GNUPG_PROGRAM environment variable. * Fix handling of a possibly non-terminated origin ID string. * Fix a file TOCTOU issue in the XML parser. * Set umask() for mkstemp() calls. * Do not free() nor unlink() an uninitialized string. * Fix printing debug message on unmatched key IDs in getKeyID(). * Update copyright years. Checksums-Sha1: 15ce406c906cd1f4ea1302b0ebcb86ab2a678e62 24010 debsig-verify-dbgsym_0.14_armhf.ddeb 2d02b614993046818f236dec93602acc4659142c 27592 debsig-verify_0.14_armhf.deb Checksums-Sha256: b15bc903649941c4618f06ea0ab468656c6102458ccbd76d082afb34ad27f062 24010 debsig-verify-dbgsym_0.14_armhf.ddeb 310ead0d353dc2017da2528fbe597767fd19cbabd802a6127745989bbe55bae5 27592 debsig-verify_0.14_armhf.deb Files: 3ab4a2b6cdbdfb9afb40c35ea1dbf273 24010 admin extra debsig-verify-dbgsym_0.14_armhf.ddeb 0b07ee9b5e1ec01c40315f6bfae51680 27592 admin optional debsig-verify_0.14_armhf.deb