https://bugzilla.redhat.com/show_bug.cgi?id=2405065



--- Comment #4 from Lukáš Zaoral <[email protected]> ---
Thanks!  Generally, LGTM.  Remarks:

The signature key used to verify the sources does not match the upstream:

https://gnupg.org/signature_key.asc :
  CHECKSUM(SHA256) this package     :
1d12afc4a2516573f661809ba68b8d955016db1101143fe5213ab5aafabd05a4
  CHECKSUM(SHA256) upstream package :
8eef03be67f3d4f0be96a6356521721388ae6477866ac0a06d3cf63e84c89a7d

Nits:
* Replace `%if ! %{with devel}` -> `%if %{without devel}`.
* Specs should use %global instead of %define unless justified.  Current use:
`%define multilib_arches`
* If possible, the `%{gpgverify}` macro should be used to verify the sources.


-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are always notified about changes to this product and component
https://bugzilla.redhat.com/show_bug.cgi?id=2405065

Report this comment as SPAM: 
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202405065%23c4

-- 
_______________________________________________
package-review mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to