Hi Matt,
Please address this Lintian output on your next upload:
Running lintian...
N:
I: rumur: file-references-package-build-path [usr/include/rumur/location.hh]
N:
N: The listed file or maintainer script appears to reference the build path
N: used to build the package as specified in the Build-Path field of the
N: .buildinfo file.
N:
N: This is likely to cause the package to be unreproducible, but it may also
N: indicate that the package will not work correctly outside of the
N: maintainer's own system.
N:
N: Please note that this tag will not appear unless the .buildinfo file
N: contains a Build-Path field. That field is optional. You may have to set
N: DEB_BUILD_OPTIONS=buildinfo=+path or use
N: --buildinfo-option=--always-include-path with dpkg-buildpackage when
N: building.
N:
N: Please refer to https://reproducible-builds.org/,
N: https://wiki.debian.org/ReproducibleBuilds/BuildinfoFiles, and the
N: dpkg-genbuildinfo(1) manual page for details.
N:
N: Visibility: info
N: Show-Always: no
N: Check: files/contents
N:
N:
I: rumur: file-references-package-build-path [usr/include/rumur/parser.yy.hh]
N:
X: rumur source: debian-watch-does-not-check-openpgp-signature [debian/watch]
N:
N: This watch file does not specify a means to verify the upstream tarball
N: using a cryptographic signature.
N:
N: If upstream distributions provides such signatures, please use the
N: pgpsigurlmangle options in this watch file's opts= to generate the URL of
N: an upstream OpenPGP signature. This signature is automatically downloaded
N: and verified against a keyring stored in debian/upstream/signing-key.asc
N:
N: Of course, not all upstreams provide such signatures but you could request
N: them as a way of verifying that no third party has modified the code after
N: its release (projects such as phpmyadmin, unrealircd, and proftpd have
N: suffered from this kind of attack).
N:
N: Please refer to the uscan(1) manual page for details.
N:
N: Visibility: pedantic
N: Show-Always: no
N: Check: debian/watch
N: Renamed from: debian-watch-does-not-check-gpg-signature
N: debian-watch-may-check-gpg-signature
N: This tag is experimental.
N:
I: Lintian run successful (worst tag: info)
Otherwise, enjoy:
$ dput ssh-upload ../rumur_2026.08.30-1_source.changes
Uploading rumur using sftp to ssh-upload (host: ssh.upload.debian.org; directory: /srv/upload.debian.org/UploadQueue/)
running allowed-distribution: check whether a local profile permits uploads to the target distribution
running protected-distribution: warn before uploading to distributions where a special policy applies
running checksum: verify checksums before uploading
running suite-mismatch: check the target distribution for common errors
running gpg: check GnuPG signatures before the upload
Logging into host ssh.upload.debian.org as tsimonq2
Uploading rumur_2026.08.30-1.dsc
Uploading rumur_2026.08.30.orig.tar.gz
Uploading rumur_2026.08.30-1.debian.tar.xz
Uploading rumur_2026.08.30-1_source.buildinfo
Uploading rumur_2026.08.30-1_source.changes
Best regards,
Simon Quigley
tsimonq2@debian.org