#1148140 libass: source no loger verifies upstream signature

#1148140#5
Date:
2026-09-17 13:20:56 UTC
From:
To:
Hi,

in updating the watch file to a v5 template in commit
https://salsa.debian.org/multimedia-team/libass/-/commit/d48f1fc8cad9a743ce05100d5d9dbb98dbf2aa00
it appears the verification of upstream signatures got lost.
No check occurs when i run it locally with devscripts 2.26.11~bpo13+1
and there are also open lintian warnings about it:
https://udd.debian.org/lintian/?packages=libass<_error=on<_warning=on<_information=on<_pedantic=on<_experimental=on&lintian_tag=#all

My naïve attempt to add add a v5 Pgp-Mode and Pgp-Sig-Url-Mangle
failed however since the mangled source URL apears to just point to the
tag on GitHub itself rather than the actual tarball URL.
So unfortunately I don’t have a quick fix to offer,
but signature files on GitHub releases seem common enough
for some other package to already handle this.

Note however, you’ll also need to refresh the upstream keys
before the next release since the old version currently stored
in debian/upstream/singing-key.asc expired a few days ago.

Cheers,
Oneric