freedomofpress / securedrop-builder

Packaging logic for building SecureDrop-related Debian packages
GNU General Public License v3.0
7 stars 11 forks source link

Release new Bullseye securedrop-keyring package #443

Closed rocodes closed 1 year ago

rocodes commented 1 year ago

The updated Bullseye version of securedrop-keyring should be released as soon as it's available, as it's a prerequisite for creating a new SDW base template as per freedomofpress/securedrop-workstation#887

rocodes commented 1 year ago

(moving this to "blocked" temporarily to get a quick opinion on https://github.com/freedomofpress/securedrop-builder/issues/448, since it affects our tagging strategy for this release)

rocodes commented 1 year ago

@zenmonkeykstop : Could I ask you to handle the (proper) tag signing for https://github.com/freedomofpress/securedrop-builder/releases/tag/securedrop-keyring-0.2.0 ?

zenmonkeykstop commented 1 year ago

A release key-signed version is now available, plz verify.

rocodes commented 1 year ago

QA

Since the package is now on apt-test, I did a very quick/basic QA:

Environment: Thinkpad T490 @ staging

However, I also notice that Debian has kept the old keyring file in place as /etc/apt/trusted.gpg.d/securedrop-keyring.gpg~, and has added /etc/apt/trusted.gpg.d/securedrop-keyring.gpg.dpkg-dist. We might not want these to stick around, particularly the former. I will file an issue.