KenanBek / KenanBek/maxDEV

Back up the Conveyor release-signing root key

Open
#8 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

release
Dominant language
Makefile
Stars
1
Forks
0
PR merge metrics
No merged PRs in 30d

Description

The Conveyor root key derives every update-trust identity: the macOS Sparkle EdDSA key, the Windows package cert (CN=maxDEV, family Maxdev_2hz5zr00knz8a) and the apt GPG key. Locate it from the machine that built 1.1.0, store a secure backup, and verify with a local conveyor make site that the produced identity matches shipped 1.1.0 (same package-family-name; appcast signature accepted by an installed 1.1.0). Gate for every future release.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by identifying the machine that built release 1.1.0 and locating the Conveyor release-signing root key. Review the macOS Sparkle identity, Windows package-family name, and apt GPG identity described in the issue, then use a local conveyor make site to compare the generated identity with shipped 1.1.0. Done means a secure backup is verified and future releases are gated on this check.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos
Domain
release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.