Skip to content

Update github cli signing key - #267

Merged
gursewak1997 merged 1 commit into
bootc-dev:mainfrom
jeckersb:github-cli-signing-key-rotation
Sep 21, 2026
Merged

gursewak1997 merged 1 commit into
bootc-dev:mainfrom
jeckersb:github-cli-signing-key-rotation

Conversation

@jeckersb

Copy link
Copy Markdown
Contributor

See cli/cli#13118 for details

Signed-off-by: John Eckersberg dev@eckersberg.com

See cli/cli#13118 for details

Signed-off-by: John Eckersberg <dev@eckersberg.com>
@gursewak1997
gursewak1997 merged commit 8c53aad into bootc-dev:main Sep 21, 2026
21 checks passed
Comment thread devenv/Containerfile.c10s
enabled=1
gpgcheck=1
gpgkey=https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x23F3D4EA75716059
gpgkey=https://cli.github.com/packages/githubcli-archive-keyring.asc

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing to change here but in practice now this is basically just chaining security of TLS for what it's worth...like in the general case in theory what we should do here is have a set of keys in a trust root we manage.

But we already rely on TLS for many other things anyways.

An alternative actually is a much-reduced set of TLS trust roots than the default ca-certificates for the build process.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants