It might be good to pin a comment that explains that users who fetch PGP keys from the keys.openpgp.org
keyserver will have trouble importing the key used to sign the source for this package, as that keyserver strips all user ID's (UID) from the key unless the owner verifies them by e-mail - which seems to be the case for that key.
GnuPG will by default refuse to import any keys without a UID, causing verification of this package to fail unless you use another keyserver. Here is a list of public keyservers that are joined in the SKS Peer Mesh network and are syncing keys between each other:
https://spider.pgpkeys.eu/sks-peers
The key used to sign this package is available on any of those.
Pinned Comments
kchr commented on 2025-09-20 16:17 (UTC)
It might be good to pin a comment that explains that users who fetch PGP keys from the
keys.openpgp.org
keyserver will have trouble importing the key used to sign the source for this package, as that keyserver strips all user ID's (UID) from the key unless the owner verifies them by e-mail - which seems to be the case for that key.GnuPG will by default refuse to import any keys without a UID, causing verification of this package to fail unless you use another keyserver. Here is a list of public keyservers that are joined in the SKS Peer Mesh network and are syncing keys between each other:
https://spider.pgpkeys.eu/sks-peers
The key used to sign this package is available on any of those.