Problem: The binary verifier counts signatures from expired and revoked keys toward --min-good-sigs.
Enough of these signatures can satisfy the threshold without any active signing key, and they are returned as good signatures.
Fix: Warn about expired and revoked signatures and exclude them from threshold counting by default.
For historical verification, --allow-expired lets expired signatures count toward the threshold. Revoked signatures remain excluded.
Expired signatures are reported separately, including in the expired_sigs JSON field.
The decision uses GnuPG’s status from the local keyring, even if the signature was created while the key was active.
This was found and disclosed responsibly by the Red Team 🟥.