Fix signing key path to avoid conflating auth and signing identities

- Change default from ~/.ssh/id_rsa to ~/.ssh/id_xbps
- Add comment explaining key separation
- Update script documentation to match

Addresses code review finding: default signing key should not be
the user's personal SSH authentication key.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-14 22:40:57 +05:30
co-authored by CommandCodeBot
parent 985efed906
commit 37a0ed7030
2 changed files with 4 additions and 4 deletions
+2 -2
View File
@@ -10,7 +10,7 @@ set -euo pipefail
#
# Environment:
# XBPS_SIGNING_KEY - Path to SSH RSA private key for XBPS signing
# (default: ~/.ssh/id_rsa)
# (default: ~/.ssh/id_xbps)
# SIGNED_BY - Signature identity string
# (default: "Fenris Packaging <packaging@bongbetic.com>")
#
@@ -25,7 +25,7 @@ GITEA_OWNER="xavierk"
GITEA_REPO="Fenris-xbps"
GITEA_BRANCH="stable"
ARCH="x86_64"
XBPS_SIGNING_KEY="${XBPS_SIGNING_KEY:-$HOME/.ssh/id_rsa}"
XBPS_SIGNING_KEY="${XBPS_SIGNING_KEY:-$HOME/.ssh/id_xbps}"
SIGNED_BY="${SIGNED_BY:-Fenris Packaging <packaging@bongbetic.com>}"
# ── Parse arguments ──────────────────────────────────────────────────────