8d3eddb Verify GPG signature of upstream tarball when building the package

5 files Authored by churchyard 2 years ago, Committed by kdudka 2 years ago,
    Verify GPG signature of upstream tarball when building the package
    
    https://docs.fedoraproject.org/en-US/packaging-guidelines/#_verifying_signatures
    
    > Any detached signature file (e.g. foo.tar.gz.asc or foo.tar.gz.sig) must be
    > uploaded to the package lookaside cache alongside the source code, while
    > the keyring must be committed directly to the package SCM.
    
    Closes: https://src.fedoraproject.org/rpms/csdiff/pull-request/1
    
        
file modified
+1 -0
file removed
-16
file modified
+10 -1
file added
+52
file modified
+1 -0