Bug#1092747: Switch to sqv breaks apt-secure overrides

Устинов Александр Евген ьевич <[email protected]>
Newsgroups gmane.linux.debian.apt.devel
Message-ID <9accee07-91cb-491d-b4f7-0e36f0a342e3__4732.1319508896$1747523727$gmane$org@ya.ru>
Similar errors in sequoia:

apt update --audit
...
Warning: https://apt.syncthing.net/dists/syncthing/InRelease: Policy 
will reject signature within a year, see --audit for details
Audit: https://apt.syncthing.net/dists/syncthing/InRelease: Sub-process 
/usr/bin/sqv returned an error code (1), error message is:
    Missing key FBA2E162F2F44657B38F0309E5665F9BD5970C47, which is 
needed to verify signature.
    Signing key on 37C84554E7E0A261E4F76E1ED26E6ED000654A3E is not bound:
               No binding signature at time 2025-05-16T22:45:26Z
      because: Policy rejected non-revocation signature 
(PositiveCertification) requiring second pre-image resistance
      because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
Warning: https://dbeaver.io/debs/dbeaver-ce/InRelease: Policy will 
reject signature within a year, see --audit for details
Audit: https://dbeaver.io/debs/dbeaver-ce/InRelease: Sub-process 
/usr/bin/sqv returned an error code (1), error message is:
    Signing key on 98F5A7CC1ABE72AC3852A007D33A1BD725ED047D is not bound:
               No binding signature at time 2025-05-04T17:39:54Z
      because: Policy rejected non-revocation signature 
(PositiveCertification) requiring second pre-image resistance
      because: SHA1 is not considered secure since 2026-02-01T00:00:00Z
Audit: Repositories should provide unencrypted signed InRelease file, 
but it was not found in 
http://linux.dropbox.com/debian/dists/trixie/InRelease.
Warning: http://linux.dropbox.com/debian/dists/trixie/Release.gpg: 
Policy will reject signature within a year, see --audit for details
Аудит: http://linux.dropbox.com/debian/dists/trixie/Release.gpg: 
Sub-process /usr/bin/sqv returned an error code (1), error message is:
    Signing key on 1C61A2656FB57B7E4DE0F4C1FC918B335044912E is not bound:
               No binding signature at time 2024-04-17T23:48:26Z
      because: Policy rejected non-revocation signature 
(PositiveCertification) requiring second pre-image resistance
      because: SHA1 is not considered secure since 2026-02-01T00:00:00Z

sqv -V
sqv 1.3.0 (sequoia-openpgp 2.0.0, using Nettle 3.10 (Cv448: true, OCB: 
true))
uname -r
6.12.27-amd64

-- 
С уважением.
   Устинов Александр Евгеньевич
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.