Fix signing key path to avoid conflating auth and signing identities
- Change default from ~/.ssh/id_rsa to ~/.ssh/id_xbps - Add comment explaining key separation - Update script documentation to match Addresses code review finding: default signing key should not be the user's personal SSH authentication key. Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
co-authored by
CommandCodeBot
parent
985efed906
commit
37a0ed7030
@@ -263,8 +263,8 @@ package: package-deb package-rpm
|
||||
|
||||
# ─── XBPS packaging (ADR 0008) ─────────────────────────────────────────────
|
||||
|
||||
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_rsa
|
||||
XBPS_SIGNED_BY ?= Fenris Packaging <packaging@bongbetic.com>
|
||||
# XBPS signing key (separate from SSH authentication key)
|
||||
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_xbps
|
||||
|
||||
package-xbps: stage
|
||||
@echo "=== Building XBPS package ==="
|
||||
|
||||
Reference in New Issue
Block a user