Unverified Commit e331892f authored by Maxim Baz's avatar Maxim Baz
Browse files

verify PGP signature of every pkg

parent 6fec8910
......@@ -154,6 +154,11 @@ async def main() -> int:
):
raise RuntimeError(f"Common fields differ in pkgbase='{pkgbase}'")
# verify PGP signature
await run(
"gpg", "--verify", pkgpath.parent / f"{pkgpath.name}.sig", pkgpath
)
pkgbases[repo][pkgbase]["packages"].append(
build_pkgmeta(pkgpath, pkginfo, pkgfiles)
)
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment