check / check (push) Waiting to run
check and fetch --require-signature compared the required fingerprint with the first key in the manifest's embedded public key block, while gpg accepted a good signature by any key in that block. Loading a signed manifest now refuses one whose embedded block holds more than one primary key, or whose signer field is not the fingerprint gpg reports for the signing key on its VALIDSIG status line. --require-signature compares with the signer field, which loading has checked. Signing now signs with and exports the key by its fingerprint, so a key ID matching two keys still writes a manifest that loads. docs/FORMAT.md states what a verifier checks. Model: opus-5-5