Fix signing key path to avoid conflating auth and signing identities
- Change default from ~/.ssh/id_rsa to ~/.ssh/id_xbps - Add comment explaining key separation - Update script documentation to match Addresses code review finding: default signing key should not be the user's personal SSH authentication key. Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
co-authored by
CommandCodeBot
parent
985efed906
commit
37a0ed7030
@@ -263,8 +263,8 @@ package: package-deb package-rpm
|
||||
|
||||
# ─── XBPS packaging (ADR 0008) ─────────────────────────────────────────────
|
||||
|
||||
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_rsa
|
||||
XBPS_SIGNED_BY ?= Fenris Packaging <packaging@bongbetic.com>
|
||||
# XBPS signing key (separate from SSH authentication key)
|
||||
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_xbps
|
||||
|
||||
package-xbps: stage
|
||||
@echo "=== Building XBPS package ==="
|
||||
|
||||
@@ -10,7 +10,7 @@ set -euo pipefail
|
||||
#
|
||||
# Environment:
|
||||
# XBPS_SIGNING_KEY - Path to SSH RSA private key for XBPS signing
|
||||
# (default: ~/.ssh/id_rsa)
|
||||
# (default: ~/.ssh/id_xbps)
|
||||
# SIGNED_BY - Signature identity string
|
||||
# (default: "Fenris Packaging <packaging@bongbetic.com>")
|
||||
#
|
||||
@@ -25,7 +25,7 @@ GITEA_OWNER="xavierk"
|
||||
GITEA_REPO="Fenris-xbps"
|
||||
GITEA_BRANCH="stable"
|
||||
ARCH="x86_64"
|
||||
XBPS_SIGNING_KEY="${XBPS_SIGNING_KEY:-$HOME/.ssh/id_rsa}"
|
||||
XBPS_SIGNING_KEY="${XBPS_SIGNING_KEY:-$HOME/.ssh/id_xbps}"
|
||||
SIGNED_BY="${SIGNED_BY:-Fenris Packaging <packaging@bongbetic.com>}"
|
||||
|
||||
# ── Parse arguments ──────────────────────────────────────────────────────
|
||||
|
||||
Reference in New Issue
Block a user