Is the need for gnupg 1.x only for the script pkg-vuln-update.sh ?
If so I added this patch locally and have used the script a couple of times since with no complaints...
--- pkg-vuln-update.sh 2016-02-26 12:28:58.650435500 +0000
+++ pkg-vuln-update.sh 2017-04-25 17:53:06.309402000 +0000
@@ -19,7 +19,7 @@
: ${CAT=cat}
: ${CP=cp}
: ${DIGEST=digest}
-: ${GPG="gpg -sta --no-options -u pkgsrc-security%NetBSD.org@localhost"}
+: ${GPG="gpg2 -sta --clear-sign --no-options -u pkgsrc-security%NetBSD.org@localhost"}
: ${GZIP="gzip -c9"}
: ${MKDIR=mkdir}
: ${PKG_ADMIN=pkg_admin}