Format: 1.8 Date: Sat, 13 Feb 2016 11:32:58 +0100 Source: debsig-verify Binary: debsig-verify Architecture: i386 Version: 0.14 Distribution: xenial-proposed Urgency: low Maintainer: Launchpad Build Daemon Changed-By: Guillem Jover Description: debsig-verify - Debian package signature verification tool Changes: debsig-verify (0.14) unstable; urgency=low . * Assume at least C89 and POSIX.1-2001. * Fix man page formatting. * Add references to debsigs(1) and gpg(1) to the man page. * Add missing man page .TH fields. * Use https instead of git or http in URLs. * Add new test case covering key to name id mapping. * Switch to use more of libdpkg instead of ad-hoc code: - Use path_make_temp_template(). - Switch from popen() to subproc_fork() and execlp(), to avoid shell invocation and unsafe argument passing. - Use the command module to invoke GnuPG instead of execlp(). * Do not use an absolute pathname to the GnuPG program. * Make the GnuPG program configurable through the DEBSIG_GNUPG_PROGRAM environment variable. * Fix handling of a possibly non-terminated origin ID string. * Fix a file TOCTOU issue in the XML parser. * Set umask() for mkstemp() calls. * Do not free() nor unlink() an uninitialized string. * Fix printing debug message on unmatched key IDs in getKeyID(). * Update copyright years. Checksums-Sha1: 3500dae63fee125080880dc8b3f50cc4e1483324 20872 debsig-verify-dbgsym_0.14_i386.ddeb 46203487dca87222c2683ea514f29c252c4f9164 31478 debsig-verify_0.14_i386.deb Checksums-Sha256: 4b4727abc8a3b7ca9d892c94048f1f937e17fe453c7b82e0635cd9845f01765d 20872 debsig-verify-dbgsym_0.14_i386.ddeb 54eb51c34c5ff752a32bc3794cfde098731149b5d39ef8795688847038e9babb 31478 debsig-verify_0.14_i386.deb Files: 01e62fa531e6c70eadcc768ce616d5e9 20872 admin extra debsig-verify-dbgsym_0.14_i386.ddeb 3429c42dc5c44e154579ffd2ff6fbee0 31478 admin optional debsig-verify_0.14_i386.deb