Hi,

I also encountered the same issue, for a repo committed on GitHub web
interface which only the commits are signed using GitHub keys; They do
not have tag signatures.

On Mon, 18 Jul 2022 09:01:25 +0300 Andrius Merkys <mer...@debian.org> wrote:
> $ git cat-file -p 1dd98b0564cb3f6bd16ce683cb755f94c10fbd82
> tree 4f4eec867a386baf9c28f21f14fe4fe7cc8f4108
> parent 8d2ce4ed2e29c39be53e39701fa6641d0f125441
> author Graham Campbell <grahamcampb...@users.noreply.github.com>
> 1655763373 +0100
> committer GitHub <nore...@github.com> 1655763373 +0100
> gpgsig -----BEGIN PGP SIGNATURE-----
> 
>  wsBcBAABCAAQBQJisPGtCRBK7hj4Ov3rIwAAxTUIAAdH68qdj8RlwkYyAnwPjarj
>  d3Fze62RSSsHGyBsJSGhrCRAbVWRuKK3Rgz6R46yxO/dtrvz7ylhx71cM3CN+F8x
>  CwI+4CDP6tx10oqz1FduN/0EYCX3FrycUR0/ENAbPk7vyhOWAjW8Buw1r+rQ09Eo
>  nptloOVzPbLtFryGAF2CUa9/OlBHk9r5n64g+PwO5oJiOsBryZlQjWxv0G1baqio
>  Lm7x09Xj1IGt9ounK6wE/nAnAzCpd7Tc/yFI65Ll68+sODWTLbY10ib1Zi7Mqi+p
>  3je59I2xXluwvFBOjQ8lKqZL+5qsyrFx1wtkYdpcdhUifeum2ljezD17Cf51mgc=
>  =AE1A
>  -----END PGP SIGNATURE-----
> 
> 
> Release 7.4.5 (#3043)

According to this document: https://git-scm.com/docs/signature-format
this seems to be a valid format commit signature, but does not have a
signed tag.

I believe uscan should give notice about this.

Thanks,
Yao Wei

Attachment: signature.asc
Description: PGP signature

Reply via email to