Otherwise untrusted repos can lie about the commit ids.
_ostree_static_delta_part_execute_async (pull_data->repo,
fetch_data->objects,
delta_data,
- TRUE,
+ /* Trust checksums if summary was gpg signed */
+ pull_data->gpg_verify_summary && pull_data->summary_data_sig,
pull_data->cancellable,
on_static_delta_written,
fetch_data);
_ostree_static_delta_part_execute_async (pull_data->repo,
fetch_data->objects,
delta_data,
- TRUE,
+ /* Trust checksums if summary was gpg signed */
+ pull_data->gpg_verify_summary && pull_data->summary_data_sig,
pull_data->cancellable,
on_static_delta_written,
fetch_data);