Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add GPG verification where possible #321

Merged
merged 2 commits into from
Dec 20, 2024

Conversation

bcressey
Copy link
Contributor

Issue number:
N/A

Description of changes:
Add a GPG verification step prior to unpacking sources for all packages where a signature is provided by the vendor.

Testing done:
Built locally.

Terms of contribution:

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

packages/runc/Cargo.toml Outdated Show resolved Hide resolved
Copy link
Contributor

@KCSesh KCSesh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - other than the remaining comments!

@bcressey
Copy link
Contributor Author

⬆️ force push to fix the stray files.

@bcressey
Copy link
Contributor Author

⬆️ force push for rebase

@bcressey
Copy link
Contributor Author

⬆️ force pushes to add the signature file for runc 1.1.15, and then to fix the hash

@bcressey bcressey merged commit 70f9dbc into bottlerocket-os:develop Dec 20, 2024
2 checks passed
@bcressey bcressey deleted the gpg-verify branch December 20, 2024 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants