On Wed, Aug 28, 2019 at 12:09:41AM -0400, Scott Kitterman wrote:
> I also check that the signature validates when I download a package from the 
> archive.  I like the fact that this signature connects to a developer key in 
> the keyring.
I think this doesn't work for e.g. old packages whose last uploader is
already retired or changed the key.

-- 
WBR, wRAR

Attachment: signature.asc
Description: PGP signature

Reply via email to