Package: devscripts Version: 2.20.5 Severity: wishlist File: /usr/bin/uscan
Please allow users to specify arbitrary scripts to verify upstream release tarballs. For example, the OpenSMTPD and OpenBSD projects use signify-openbsd (from the signify-openbsd package) instead of GnuPG to verify their releases. For example, to verify https://opensmtpd.org/archives/opensmtpd-6.8.0p2.tar.gz one goes: rak@zeta:/tmp$ wget --quiet https://opensmtpd.org/archives/opensmtpd-20181026.pub # (In principle, you should already have saved the public key # opensmtpd-20181026.pub somewhere and verified it out of band.) rak@zeta:/tmp$ wget --quiet https://opensmtpd.org/archives/opensmtpd-6.8.0p2.tar.gz rak@zeta:/tmp$ wget --quiet https://opensmtpd.org/archives/opensmtpd-6.8.0p2.sum.sig rak@zeta:/tmp$ signify-openbsd -C -p opensmtpd-20181026.pub -x opensmtpd-6.8.0p2.sum.sig Signature Verified opensmtpd-6.8.0p2.tar.gz: OK -- Package-specific info: --- /etc/devscripts.conf --- Empty. --- ~/.devscripts --- Not present -- System Information: Debian Release: bullseye/sid APT prefers unstable-debug APT policy: (500, 'unstable-debug'), (500, 'unstable'), (1, 'experimental-debug'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 5.10.0-1-amd64 (SMP w/4 CPU threads) Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE Locale: LANG=en_CA.UTF-8, LC_CTYPE=en_CA.UTF-8 (charmap=UTF-8) (ignored: LC_ALL set to en_CA.UTF-8), LANGUAGE not set Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages devscripts depends on: ii dpkg-dev 1.20.7.1 ii fakeroot 1.25.3-1.1 ii file 1:5.39-3 ii gnupg 2.2.20-1 ii gnupg2 2.2.20-1 ii gpgv 2.2.20-1 ii gpgv2 2.2.20-1 ii libc6 2.31-9 ii libfile-dirlist-perl 0.05-2 ii libfile-homedir-perl 1.006-1 ii libfile-touch-perl 0.11-1 ii libfile-which-perl 1.23-1 ii libipc-run-perl 20200505.0-1 ii libmoo-perl 2.004004-1 ii libwww-perl 6.52-1 ii patchutils 0.4.2-1 ii perl 5.32.0-6 ii python3 3.9.1-1 ii sensible-utils 0.0.14 ii wdiff 1.2.2-2+b1 Versions of packages devscripts recommends: ii apt 2.1.18 ii curl 7.74.0-1 ii dctrl-tools 2.24-3+b1 ii debian-keyring 2020.12.24 ii dput 1.1.0 ii equivs 2.3.1 ii libdistro-info-perl 0.24 ii libdpkg-perl 1.20.7.1 ii libencode-locale-perl 1.05-1.1 ii libgit-wrapper-perl 0.048-1 ii libgitlab-api-v4-perl 0.25-2 ii liblist-compare-perl 0.55-1 ii liblwp-protocol-https-perl 6.10-1 ii libsoap-lite-perl 1.27-1 ii libstring-shellquote-perl 1.04-1 ii libtry-tiny-perl 0.30-1 ii liburi-perl 5.05-1 pn licensecheck <none> ii lintian 2.104.0 ii man-db 2.9.3-2 ii patch 2.7.6-7 ii pristine-tar 1.49 ii python3-apt 2.1.7 ii python3-debian 0.1.39 ii python3-magic 2:0.4.15-5 ii python3-requests 2.25.1+dfsg-2 ii python3-unidiff 0.5.5-2 ii python3-xdg 0.27-2 ii strace 5.10-1 ii unzip 6.0-26 ii wget 1.21-1+b1 ii xz-utils 5.2.5-1.0 Versions of packages devscripts suggests: ii adequate 0.15.3 ii at 3.1.23-1.1 ii autopkgtest 5.15 pn bls-standalone <none> pn bsd-mailx | mailx <none> ii build-essential 12.9 pn check-all-the-things <none> pn cvs-buildpackage <none> ii debhelper 13.3.1 pn devscripts-el <none> ii diffoscope 164 pn disorderfs <none> pn dose-extra <none> pn duck <none> pn faketime <none> ii gnuplot 5.4.1+dfsg1-1 ii gnuplot-qt [gnuplot] 5.4.1+dfsg1-1 pn how-can-i-help <none> ii libauthen-sasl-perl 2.1600-1.1 pn libdbd-pg-perl <none> ii libfile-desktopentry-perl 0.22-2 pn libnet-smtps-perl <none> pn libterm-size-perl <none> ii libtimedate-perl 2.3300-1 pn libyaml-syck-perl <none> pn mmdebstrap <none> ii mozilla-devscripts 0.54.2 pn mutt <none> ii openssh-client [ssh-client] 1:8.4p1-3 ii piuparts 1.1.1 pn postgresql-client <none> ii quilt 0.66-2.1 pn ratt <none> ii reprotest 0.7.15 ii svn-buildpackage 0.8.7 ii w3m 0.5.3+git20210102-1 -- no debconf information -- |)|/ Ryan Kavanagh | GPG: 4E46 9519 ED67 7734 268F |\|\ https://rak.ac | BD95 8F7B F8FC 4A11 C97A