Sign (GPG) extensions releases
Closed
Bitesize
- Dominant language
- Shell
- Stars
- 1.2k
- Forks
- 146
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 20
Description
Right now, extensions are not signed, and use verify=no.
They should be signed with the same key as the OS partitions
Contributor guide
Research direction
Start by locating the extension release configuration and the current verify=no setting in the OS build system. Then trace how OS partitions are signed and determine how that signing key is used. Done means extension releases are signed with the same key and no longer require verification to be disabled.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- shell
- Domain
- build-system, release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100