Hi. I help maintain this package in Debian. With latest update to 0.16.0 we got a self-test failure below. This may be due to some build dependency that is out of version, but do you have any ideas what could trigger this? See build log that contains versions of various libraries below.
https://salsa.debian.org/jas/gitsign/-/jobs/9740590#L5095
=== RUN TestDuplicateTreeTrustConfusion
=== RUN TestDuplicateTreeTrustConfusion/signature_is_a_genuine_forgery_against_the_re-encoded_form
invalid_object_test.go:106: pre-fix behavior check: expected signature to verify over re-encoded bytes (proves the PoC is genuine), got: failed to verify detached signature: invalid message digest
=== RUN TestDuplicateTreeTrustConfusion/fix:_signature_fails_to_verify_against_the_raw_malformed_bytes
=== RUN TestDuplicateTreeTrustConfusion/fix_accepts_the_legitimate_commit_and_signature_verifies
--- FAIL: TestDuplicateTreeTrustConfusion (0.01s)
--- FAIL: TestDuplicateTreeTrustConfusion/signature_is_a_genuine_forgery_against_the_re-encoded_form (0.00s)
--- PASS: TestDuplicateTreeTrustConfusion/fix:_signature_fails_to_verify_against_the_raw_malformed_bytes (0.00s)
--- PASS: TestDuplicateTreeTrustConfusion/fix_accepts_the_legitimate_commit_and_signature_verifies (0.00s)
FAIL
Thanks,
Simon
Hi. I help maintain this package in Debian. With latest update to 0.16.0 we got a self-test failure below. This may be due to some build dependency that is out of version, but do you have any ideas what could trigger this? See build log that contains versions of various libraries below.
https://salsa.debian.org/jas/gitsign/-/jobs/9740590#L5095
Thanks,
Simon