Adam Majer pointed out in [1] the way were signing releases was
unusual. Neither Carl nor I could think of a good reason for
explicitely signing the checksum (internally of course that's what GPG
is going anyway).
[1] mid:
b3fd556d-c346-7af9-a7a2-
13b0f3235071@suse.de
ELPA_FILE:=$(PACKAGE)-emacs-$(ELPA_VERSION).tar
DEB_TAR_FILE=$(PACKAGE)_$(VERSION).orig.tar.gz
SHA256_FILE=$(TAR_FILE).sha256
-GPG_FILE=$(SHA256_FILE).asc
+GPG_FILE=$(TAR_FILE).asc
PV_FILE=bindings/python/notmuch/version.py
$(SHA256_FILE): $(TAR_FILE)
sha256sum $^ > $@
-$(GPG_FILE): $(SHA256_FILE)
- gpg --armor --sign $^
+$(GPG_FILE): $(TAR_FILE)
+ gpg --armor --detach-sign $^
.PHONY: dist
dist: $(TAR_FILE)