Bug#742552: developers-reference should encourage verification of upstream cryptographic signatures

"Serafeim (Serafi) Zanikolas" <[email protected]> Tue, 19 May 2026 21:29:42 +0200
Newsgroups gmane.linux.debian.devel.policy
Message-ID <DIMWHOPV7U29.KFV8UQGQ1WMY__7035.85566241003$1779219089$gmane$org@debian.org>
tags 742552 + patch
thanks

hi,

this bug was originally cloned off policy bug #732445, which has been long
fixed.

please find attached a patch for devref, to (i) encourage the use of the sig
verification functionality, when applicable, (ii) point to Policy for details on
how to use it.  (this seems backwards to me: ideally, devref would have the
details and Policy would link to it, but nevermind)

thanks,
serafi
0001-best-pkging-practices-encourage-automatic-verificati.patch (text/x-patch, 1.2 KB)
From 764e660d684f4fc86c650b55927e34bb91ef5cdf Mon Sep 17 00:00:00 2001
From: "Serafeim (Serafi) Zanikolas" <[email protected]>
Date: Tue, 19 May 2026 21:20:19 +0200
Subject: [PATCH] best-pkging-practices: encourage automatic verification of
 upstream release signatures

---
 source/best-pkging-practices.rst | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/source/best-pkging-practices.rst b/source/best-pkging-practices.rst
index 3d1fd75..3dea1c4 100644
--- a/source/best-pkging-practices.rst
+++ b/source/best-pkging-practices.rst
@@ -554,8 +554,13 @@ is good news!
 Best practices around security
 ================================================================================================================================
 
-A set of security suggestions related to packaging can be found at
-https://wiki.debian.org/Hardening.
+When an upstream publishes a cryptographic signature for every new release, you
+should setup ``uscan`` to automatically verify the latter. For details, refer to
+the section on ``Upstream source location: "debian/watch"`` in the The Debian
+Policy Manual.
+
+https://wiki.debian.org/Hardening has suggestions on how to build security
+hardened executables.
 
 .. _bpp-debian-maint-scripts:
 
-- 
2.47.3
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEA2RWqo7IwLCLSFYbT59tVQ7WEioFAmoMuiYACgkQT59tVQ7W
EiotHA//YQHxzHgDTCRvAwVZjFQZS6eJ1vskLbjCd2MeDIK40v2yS6+qAFPPVnUM
z5mkjTbnDVVeAHBsnSKFlW2na0smHRtHJBBSmMlwFAiJZdqlpdo675VF+lyLHTtx
JFRtPefQNPFJ4gEBGDoLkbBG239D8M94L1VKE20MdI8HUZjmknAXnjjJSz7+JyHf
nm0BXt7ANR3llrikc56hfd/rRaF+6YVsAXXnhNc6h1UUhu03gv6Oa87DrdOpr59N
rXo9tXky5rRoIAzNLzhDMc1SY3Z6mp/HxBrLhvwSVHz3mVud9cJsVgeO9r2LSph4
+lRRX4SY1TALhC3KwM2IP9JhWami3ezw7Xg4K+OoYK616wbcEh4/NTXK6mkB/0Xc
T2HSi+qut21zhc/erWPgYlDYsO2FoNHh2A/VT6qphyJooYU57GV3zu/hR6JU+JSt
hBS10XPxtFigkDe42VelFgWOtUNM0T4IAr8JfSbMEpDGNfcyVCwqvln6OP1c1pfa
AJPh1AdyQfcBGMrfz2AR0ujWI89hcS5kDyEtVjzHRe1okk/N0xqSpZJGrm7zq7EB
oo2GWYYpeTlj5ZKJu0LgtDtxX4O5tfMsuHmeeqSv6TvNWqBP6INM2bSp4+9JgVvq
/gROpD+4TtecDMBx/EwF/yS6GwqwNBFBQEpn2nRuzUR0Yd9/E50=
=GMxJ
-----END PGP SIGNATURE-----