@arse More specifically, the key has expired:
==> Verifying source file signatures with gpg...
libvorbis-1.3.7.tar.gz ... Passed (WARNING: the key has expired.)
==> WARNING: Warnings have occurred while verifying the signatures.
Please make sure you really trust them.
However it is still the same one key that signed the source tarball (see the green checkmarks or the Verified label here).
Since it builds for me in a clean chroot and libvorbis
from the official repo still contains the same key, I guess nothing will change until a potential future update. If you're not happy, you can just comment/delete it in your local PKGBUILD.
Pinned Comments
neitsab commented on 2021-05-16 23:17 (UTC) (edited on 2024-11-15 15:41 (UTC) by neitsab)
This was a somehow tricky update, as what was described as a simple bugfix update to the patches turned out to also include a stealth update to aoTuVb.03, leading to quite a few packaging changes that were not immediately clear.
Most notably, since the patch maintainer updated them without changing the file names, I had to find a way to force a redownload of the files for all users. I did it via a custom variable using the date of the latest patch update, using it to rename the files.
I suggest that this package move to enzo1982's Github repo as upstream so as to simplify maintenance, however that means either:
What do people here think about this issue?
Cheers