DSCVERIFY(1) General Commands Manual DSCVERIFY(1)
dscverify - verify the validity of a Debian package
| Use Case | Command | Description |
|---|---|---|
| đĻ Verify a .dsc file | dscverify file.dsc | Check GPG signature and all checksums (MD5, SHA1, SHA256) |
| đ Use custom keyring | dscverify --keyring /path/to/keyring.gpg file.dsc | Add an extra keyring for GPG verification |
| đĢ Skip signature check | dscverify --nosigcheck file.dsc | Only verify file sizes and checksums, not signatures |
| đ Use only specified keyrings | dscverify --no-default-keyrings --keyring mykeyring.gpg file.dsc | Don't use default Debian keyrings |
| â Display help | dscverify --help | Show help message and exit |
dscverify [--keyring keyring] ... changes_or_buildinfo_or_dsc_filename ...
dscverify checks that the GPG signatures on the given .changes, .buildinfo or .dsc files are good signatures made by keys in the current Debian keyrings, found in the debian-keyring package. (Additional keyrings can be specified using the --keyring option any number of times.) It then checks that the other files listed in the .changes, .buildinfo or .dsc files have the correct sizes and checksums (MD5 plus SHA1 and SHA256 if the latter are present). The exit status is 0 if there are no problems and non-zero otherwise.
--keyring keyringAdd keyring to the list of keyrings to be used.
--no-default-keyringsDo not use the default set of keyrings.
--no-conf, --noconfDo not read any configuration files. This can only be used as the first option given on the command-line.
--nosigcheck, --no-sig-check, -uSkip the signature verification step. That is, only verify the sizes and checksums of the files listed in the .changes, .buildinfo or .dsc files.
--verboseDo not suppress GPG output.
--help, -hDisplay a help message and exit successfully.
--versionDisplay version and copyright information and exit successfully.
The two configuration files /etc/devscripts.conf and ~/.devscripts are sourced by a shell in that order to set configuration variables. Environment variable settings are ignored for this purpose. If the first command line option given is --noconf or --no-conf, then these files will not be read. The currently recognised variable is:
Please note that the keyring provided by the debian-keyring package can be slightly out of date. The latest version can be obtained with rsync, as documented in the README that comes with debian-keyring. If you sync the keyring to a non-standard location (see below), you can use the possibilities to specify extra keyrings, by either using the above mentioned configuration option or the --keyring option.
Below is an example for an alias:
alias dscverify='dscverify --keyring ~/.gnupg/pubring.gpg'
By default dscverify searches for the debian-keyring in the following locations:
~/.gnupg/trustedkeys.gpg/srv/keyring.debian.org/keyrings/debian-keyring.gpg/usr/share/keyrings/debian-keyring.gpg/usr/share/keyrings/debian-maintainers.gpg/usr/share/keyrings/debian-nonupload.gpggpg(1), gpg2(1), devscripts.conf(5)
dscverify was written by Roderick Schertler <roderick AT argon.org> and posted on the debian-devel AT lists.org mailing list, with several modifications by Julian Gilbey <jdg AT debian.org>.
DEBIAN Debian Utilities DSCVERIFY(1)
Generated by phpman v4.9.26-1-g511901d Author: Che Dong Under GNU General Public License
2026-08-09 10:15 @2600:1f28:365:80b0:50b3:453e:ff52:20f7
CrawledBy CCBot/2.0 (https://commoncrawl.org/faq/)
Enhanced by LLM: deepseek-v4-flash / taotoken.net / www.chedong.com - original format