Rebuild Todo List Fix reproducibility of packages broken by PyPI removing signature files
Since PyPI first deprecated the use of OpenPGP signatures [1] and then broke downloading existing signature files via predictable URLs(!), the reproducibility of some packages [2] is now broken because of that.
To ensure the continued chain of trust as well as the reproducibility of packages, please get in touch with the affected upstreams and ask for signature files for existing (if feasible/relevant) and upcoming releases to be provided elsewhere (e.g. their own project space at their respective source forge).
If a request for signature files fails, non-predictable PyPI URLs can be used. For example: https://files.pythonhosted.org/packages/1d/c7/28220d37e041fe1df03e857fe48f768dcd30cd151480bf6f00da8713214a/py-ubjson-0.16.1.tar.gz.asc.
Rebuilds go straight to the stable repositories.
[1] https://blog.pypi.org/posts/2023-05-23-removing-pgp/
[2] https://gitlab.archlinux.org/search?group_id=11323&nav_source=navbar&scope=blobs&search=%22pythonhosted%22+%2B+%28%22.asc%22+%7C+%22.sig%22%29+filename%3A*PKGBUILD
Filter Todo List Packages
Arch | Repository | Name | Current Version | Staging Version | Maintainers | Status | Last Touched By |
---|---|---|---|---|---|---|---|
any | Extra | mailman3-hyperkitty | 1.2.1-5 | dvzrv | Complete | dvzrv | |
any | Extra | nikola | 8.3.1-2 | Lahwaacz, dvzrv | Complete | dvzrv | |
x86_64 | Extra | picard | 2.12.3-2 | dvzrv | Complete | dvzrv | |
any | Extra | python-authheaders | 0.16.3-2 | dvzrv | Complete | dvzrv | |
any | Extra | python-characteristic | Complete | polyzen | |||
any | Extra | python-flufl.testing | Complete | dvzrv | |||
x86_64 | Extra | python-html5-parser | 0.4.12-3 | jelle | Complete | dvzrv | |
any | Extra | python-josepy | 1.14.0-4 | grawlinson | Complete | grawlinson | |
any | Extra | python-lazr.config | 3.0-4 | dvzrv | Complete | dvzrv | |
any | Extra | python-lazr.delegates | 2.1.0-4 | dvzrv | Complete | dvzrv | |
x86_64 | Extra | python-librabbitmq | Complete | dvzrv | |||
any | Extra | python-mailmanclient | 3.3.5-7 | dvzrv | Complete | dvzrv | |
any | Extra | python-markdown-math | 0.8-8 | farseerfc | Complete | dvzrv | |
any | Extra | python-markups | 3.1.3-10 | jlichtblau | Complete | dvzrv | |
any | Extra | python-mechanize | 1:0.4.10-2 | jelle | Complete | dvzrv | |
any | Extra | python-progressbar | 4.5.0-2 | jelle, dvzrv | Complete | dvzrv | |
any | Extra | python-scramp | Complete | yan12125 | |||
x86_64 | Extra | python-ubjson | 0.16.1-8 | yan12125 | Complete | yan12125 | |
any | Extra | retext | 8.0.2-3 | farseerfc | Complete | dvzrv |