# Upstream releases signed Git tags, rather than signed tarballs
holes source:  debian-watch-does-not-check-gpg-signature
holes source:  debian-watch-could-verify-download