In rpm-based systems, we can easily see if there is a signature associated with an rpm file:
rpm -qpi <rpm-file.rpm> | grep -i signature
For .deb files, we can see the package information but it doesn't include the information of whether a signature is associated or not:
dpkg-deb -I uma-18feb-latest.deb
Is there a way in Ubuntu to see the signature without using the following command which actually verifies the signature?
dpkg-sig --verify <deb-file.deb>
ar -x package.deb
will list the files in raw archive, and signed packages will have files starting with_gpg
. – Stephen Kitt Apr 01 '21 at 15:21