Problem: The binary verifier counts signatures from expired and revoked keys toward --min-good-sigs.
Enough of these signatures can satisfy the threshold without any active signing key, and they are returned as good signatures.
Fix: Warn about expired and revoked signatures and exclude them from threshold counting by default.
For historical verification, expired signatures can count toward the threshold with --allow-expired or BINVERIFY_ALLOW_EXPIRED, including signatures created after key expiry. Revoked signatures remain excluded.
Expired signatures are reported separately, including in the expired_sigs field in successful JSON output.
The decision uses GnuPG’s current key status from the local keyring, even if the signature was created while the key was active.
This was found and disclosed responsibly by the Red Team 🟥.