Sean Whitton <spwhit...@spwhitton.name> writes:

> That should be enough!  If you were able to do at least one upload using
> 'dgit push-source' for each package to confirm everything is okay, that
> would be great.

I'll try.  I got a SSH push warning on first use -- how would I verify
this host SSH key?  What's the risk uploaders getting MITM'ed here?

The authenticity of host 'push.dgit.debian.org (2001:41b8:202:deb::311:78)' 
can't be established.
ED25519 key fingerprint is SHA256:O4i2PPFELuj49wYZSwLt+a2r356sB19KMCFhrUKkYiM.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? 

/Simon

Attachment: signature.asc
Description: PGP signature

Reply via email to