 xavierkandCommandCodeBot
|
d8fa6df072
|
signing: rpm payload signing, key publication, consumer repo setup for #51
Implement the signing and consumer-repo trust infrastructure:
- Makefile: add generate-test-key, sign-rpm, checksums, clearsign targets;
make release now automates the full build→sign→checksum→clearsign flow
- Key ceremony: document the import→sign→delete lifecycle, key rotation
outline, and private-key-in-password-manager policy
- Public key: update placeholder with raw URL, algorithm, and ceremony ref
- Consumer docs: README now covers apt signed-by keyring flow, dnf repo
file setup, signature verification commands, and migration runbook link
- Release spec: updated to reference ceremony doc and rpmsign workflow
- Tests: 36 structural signing tests (nfpm config, Makefile targets,
repo file, key publication, ceremony doc, consumer docs, spec refs)
plus throwaway-key RPM signature and clearsign mechanics; no network
or real key required
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
|
2026-09-03 14:14:55 +05:30 |
|