[arch-commits] Commit in (11 files)

Sébastien Luttringer seblu at archlinux.org
Tue Jan 6 01:12:29 UTC 2015


    Date: Tuesday, January 6, 2015 @ 02:12:28
  Author: seblu
Revision: 228691

https://www.archlinux.org/todo/validpgpkeys-integrity-check/

Modified:
  bind/trunk/PKGBUILD
  conntrack-tools/trunk/PKGBUILD
  diffutils/trunk/PKGBUILD
  grep/trunk/PKGBUILD
  gzip/trunk/PKGBUILD
  less/trunk/PKGBUILD
  patch/trunk/PKGBUILD
  pcre/trunk/PKGBUILD
  sed/trunk/PKGBUILD
  tar/trunk/PKGBUILD
  which/trunk/PKGBUILD

--------------------------------+
 bind/trunk/PKGBUILD            |    1 +
 conntrack-tools/trunk/PKGBUILD |    1 +
 diffutils/trunk/PKGBUILD       |    1 +
 grep/trunk/PKGBUILD            |    1 +
 gzip/trunk/PKGBUILD            |    1 +
 less/trunk/PKGBUILD            |    1 +
 patch/trunk/PKGBUILD           |    1 +
 pcre/trunk/PKGBUILD            |    1 +
 sed/trunk/PKGBUILD             |    7 ++++---
 tar/trunk/PKGBUILD             |    1 +
 which/trunk/PKGBUILD           |    7 ++++---
 11 files changed, 17 insertions(+), 6 deletions(-)

Modified: bind/trunk/PKGBUILD
===================================================================
--- bind/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ bind/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -21,6 +21,7 @@
         'var/named/localhost.ip6.zone'
         'var/named/empty.zone')
 install=$pkgname.install
+validpgpkeys=('2B48A38AE1CF9886435F89EE45AC7857189CDBC5') # ISC, Inc
 source=("http://ftp.isc.org/isc/bind9/${_pkgver}/bind-${_pkgver}.tar.gz"{,.asc}
         'tmpfiles.conf'
         'sysusers.conf'

Modified: conntrack-tools/trunk/PKGBUILD
===================================================================
--- conntrack-tools/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ conntrack-tools/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -16,6 +16,7 @@
          'libnetfilter_cthelper'
          'libnetfilter_queue')
 backup=('etc/conntrackd.conf')
+validpgpkeys=('57FF5E9C9AA67A860B557AF7A4111F89BB5F58CC') # Netfilter Core Team
 source=("http://www.netfilter.org/projects/$pkgname/files/$pkgname-$pkgver.tar.bz2"{,.sig}
         'conntrackd.service')
 install=$pkgname.install

Modified: diffutils/trunk/PKGBUILD
===================================================================
--- diffutils/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ diffutils/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -13,6 +13,7 @@
 groups=('base')
 depends=('glibc' 'bash')
 install=diffutils.install
+validpgpkeys=('155D3FC500C834486D1EEA677FD9FCCB000BEEEE') # Jim Meyering
 source=("ftp://ftp.gnu.org/gnu/$pkgname/$pkgname-$pkgver.tar.xz"{,.sig})
 md5sums=('99180208ec2a82ce71f55b0d7389f1b3'
          '203a2f2101dfcc09cdac655be353fd78')

Modified: grep/trunk/PKGBUILD
===================================================================
--- grep/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ grep/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -14,6 +14,7 @@
 depends=('glibc' 'pcre')
 makedepends=('texinfo')
 install=$pkgname.install
+validpgpkeys=('155D3FC500C834486D1EEA677FD9FCCB000BEEEE') # Jim Meyering
 source=("ftp://ftp.gnu.org/gnu/$pkgname/$pkgname-$pkgver.tar.xz"{,.sig})
 md5sums=('43c48064d6409862b8a850db83c8038a'
          'SKIP')

Modified: gzip/trunk/PKGBUILD
===================================================================
--- gzip/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ gzip/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -13,6 +13,7 @@
 groups=('base' 'base-devel')
 depends=('glibc' 'bash' 'less')
 install=gzip.install
+validpgpkeys=('155D3FC500C834486D1EEA677FD9FCCB000BEEEE') # Jim Meyering
 source=("ftp://ftp.gnu.org/pub/gnu/gzip/gzip-$pkgver.tar.xz"{,.sig})
 md5sums=('da981f86677d58a106496e68de6f8995'
          'SKIP')

Modified: less/trunk/PKGBUILD
===================================================================
--- less/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ less/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -12,6 +12,7 @@
 url='http://www.greenwoodsoftware.com/less'
 groups=('base')
 depends=('glibc' 'ncurses' 'pcre')
+validpgpkeys=('AE27252BD6846E7D6EAE1DD6F153A7C833235259') # Mark Nudelman
 source=("http://www.greenwoodsoftware.com/$pkgname/$pkgname-$pkgver.tar.gz"{,.sig})
 md5sums=('9a40d29a2d84b41f9f36d7dd90b4f950'
          'SKIP')

Modified: patch/trunk/PKGBUILD
===================================================================
--- patch/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ patch/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -14,6 +14,7 @@
 depends=('glibc' 'attr')
 makedepends=('ed')
 optdepends=('ed: for patch -e functionality')
+validpgpkeys=('6CEF9231D6BF2594FABA779EF7E872FEB97154D3') # Andreas Gruenbacher
 source=("ftp://ftp.gnu.org/gnu/$pkgname/$pkgname-$pkgver.tar.xz"{,.sig}
         'patch-2.7.1-initialize-data-structures-early-enough.patch')
 md5sums=('e9ae5393426d3ad783a300a338c09b72'

Modified: pcre/trunk/PKGBUILD
===================================================================
--- pcre/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ pcre/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -12,6 +12,7 @@
 url='http://www.pcre.org/'
 license=('BSD')
 depends=('gcc-libs' 'readline' 'zlib' 'bzip2' 'bash')
+validpgpkeys=('45F68D54BBE23FB3039B46E59766E084FB0F43D8') # Philip Hazel
 source=("ftp://ftp.csx.cam.ac.uk/pub/software/programming/pcre/$pkgname-$pkgver.tar.bz2"{,.sig}
         '001-fix-heap-overflow.patch')
 md5sums=('b767bc9af0c20bc9c1fe403b0d41ad97'

Modified: sed/trunk/PKGBUILD
===================================================================
--- sed/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ sed/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -14,9 +14,10 @@
 depends=('glibc' 'acl' 'attr')
 makedepends=('gettext')
 install=sed.install
-source=("ftp://ftp.gnu.org/pub/gnu/sed/$pkgname-$pkgver.tar.gz"{,.sig})
-md5sums=('4111de4faa3b9848a0686b2f260c5056'
-         '86a5ab72f414d4cb38126e8e27cf0101')
+# gpg key of Paolo Bonzini has been revoked in 2013, not using it
+# check if a new one is issued in the next release
+source=("ftp://ftp.gnu.org/pub/gnu/sed/$pkgname-$pkgver.tar.gz")
+md5sums=('4111de4faa3b9848a0686b2f260c5056')
 
 build() {
   cd $pkgname-$pkgver

Modified: tar/trunk/PKGBUILD
===================================================================
--- tar/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ tar/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -14,6 +14,7 @@
 depends=('glibc' 'acl' 'attr')
 options=('!emptydirs')
 install=tar.install
+validpgpkeys=('325F650C4C2B6AD58807327A3602B07F55D0C732') # Sergey Poznyakoff
 source=("ftp://ftp.gnu.org/gnu/$pkgname/$pkgname-$pkgver.tar.xz"{,.sig})
 md5sums=('49b6306167724fe48f419a33a5beb857'
          'SKIP')

Modified: which/trunk/PKGBUILD
===================================================================
--- which/trunk/PKGBUILD	2015-01-05 23:21:42 UTC (rev 228690)
+++ which/trunk/PKGBUILD	2015-01-06 01:12:28 UTC (rev 228691)
@@ -13,9 +13,10 @@
 groups=('base' 'base-devel')
 depends=('glibc' 'bash')
 install=which.install
-source=("http://ftp.gnu.org/gnu/$pkgname/$pkgname-$pkgver.tar.gz"{,.sig})
-md5sums=('95be0501a466e515422cde4af46b2744'
-         'SKIP')
+# gpg key is using deprecated md5 algo, do not use
+# check if a new one is issued in the next release
+source=("http://ftp.gnu.org/gnu/$pkgname/$pkgname-$pkgver.tar.gz")
+md5sums=('95be0501a466e515422cde4af46b2744')
 
 build() {
   cd $pkgname-$pkgver



More information about the arch-commits mailing list