Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add securedrop-workstation-dom0-config 0.6.3 signed package #35

Merged
merged 1 commit into from
Jun 24, 2022

Conversation

sssoleileraaa
Copy link
Contributor

@sssoleileraaa sssoleileraaa commented Jun 24, 2022

Description

Package being released: securedrop-workstation-dom0-config 0.6.3
Package tag: https://github.com/freedomofpress/securedrop-workstation/releases/tag/0.6.3
Build logs: https://github.com/freedomofpress/build-logs/blob/main/workstation/securedrop-workstation-dom0-config-0.6.3
Test signing key used to sign package and tag: https://github.com/freedomofpress/securedrop-workstation-dev-rpm-packages-lfs/blob/HEAD/pubkeys/test.key

Release tracking issue: freedomofpress/securedrop-yum-prod#33

Checklist for PR owner

Checklist for reviewer

  • CI is passing
  • The commits being released are what you expect (see freedomofpress/securedrop-workstation@0.6.2...0.6.3)
  • The RPM is signed with the test signing key
    • Download the signed RPM from this PR
    • Run rpm -qi <signed-rpm> to get the KEY ID
    • Run gpg -k <KEY ID> to verify that it matches the test signing key (make sure you have the test signing key referenced in the PR description in your GPG keyring)
  • The Unsigned RPM checksum matches what's in the build logs
    • Download the signed RPM from this PR (if you haven't already)
    • Run rpm --delsign <signed-rpm> to remove the signature (do this on same OS used to build the package, in this case it's Debian)
    • Run sha256sum <unsigned-rpm> and compare

@sssoleileraaa sssoleileraaa marked this pull request as ready for review June 24, 2022 20:41
@eaon eaon self-requested a review June 24, 2022 21:14
@eaon
Copy link
Contributor

eaon commented Jun 24, 2022

Looks good!

And a weird one again, the OS version matters too - rpm --delsign on buster gave the right hash, on bullseye it does not (it gives the same hash as Fedora 35 🤷)

@eaon eaon merged commit 5737b00 into main Jun 24, 2022
@eaon eaon deleted the release-dom0-config-0.6.3 branch June 24, 2022 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants