[pacman-dev] %PGPSIG% vs .sig

Bruno Pagani bruno.n.pagani at gmail.com
Mon May 29 20:37:02 UTC 2017


Le 29/05/2017 à 07:31, Brandon Milton a écrit :

> While exploring the pacman mirror layout (ie what is hosted by mirrors), I
> noticed that for each package, there are two copies of the same signature:
> one in %PGPSIG% in the desc file of the database and one in the
> {package}-{version}.pkg.tar.gz.sig file
>
> I understand that for the AUR, the .sig file is necessary given that there
> is no official database.

Just one thing: AFAIK, they are no .sig files in the AUR.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 520 bytes
Desc: OpenPGP digital signature
URL: <https://lists.archlinux.org/pipermail/pacman-dev/attachments/20170529/1be82080/attachment.asc>


More information about the pacman-dev mailing list