scala-cli icon indicating copy to clipboard operation
scala-cli copied to clipboard

Scala-cli .deb file is not signed

Open DavidGoodenough opened this issue 10 months ago • 1 comments

Version(s) All versions

Describe the bug On a Debian sid system, APT is getting increasingly insistent that.deb files loaded from repositories should be signed. Scala-cli is not and should be.

To Reproduce If you use Debian sid with an up to date apt , if you run apt update then it will emark that the repository does not have a signed by value, especially if you have used the apt modernize-sources command to use the new sources file format.

Expected behaviour A distribution key pair should be generated and the .deb should be signed with the private ket and the public key should be made available for download and use in the signed by clause.

DavidGoodenough avatar Feb 16 '25 19:02 DavidGoodenough

To complete the upgrade to the scala-cli.deb file, there needs to be a changelog available when an upgrade happens. There is I think a git command which generates this from the git change history.

DavidGoodenough avatar Mar 11 '25 19:03 DavidGoodenough