Fix signing key path to avoid conflating auth and signing identities

- Change default from ~/.ssh/id_rsa to ~/.ssh/id_xbps
- Add comment explaining key separation
- Update script documentation to match

Addresses code review finding: default signing key should not be
the user's personal SSH authentication key.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-14 22:40:57 +05:30
co-authored by CommandCodeBot
parent 985efed906
commit 37a0ed7030
2 changed files with 4 additions and 4 deletions
+2 -2
View File
@@ -263,8 +263,8 @@ package: package-deb package-rpm
# ─── XBPS packaging (ADR 0008) ─────────────────────────────────────────────
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_rsa
XBPS_SIGNED_BY ?= Fenris Packaging <packaging@bongbetic.com>
# XBPS signing key (separate from SSH authentication key)
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_xbps
package-xbps: stage
@echo "=== Building XBPS package ==="