Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upkeys: add codebytere's gpg key #956
Conversation
|
@codebytere can you allow contributors to add commits to this PR< I will update the images before merging. |
|
@LaurentGoderre |
|
I didn't try. I also didn't see anything in the UI indicating it was enabled so KI wrongly assumed it wasn't.... :S |
|
ah gotcha, np let me know if there are any issues! |
ozbillwang
commented
Aug 21, 2019
|
could you please nicely explain, why this official image need be inserted some personal PGP keys? Will this be security issue for us as customers, who pull the images and used in our produciton environment? |
|
@ozbillwang we need those keys to validate that the node package we include in the image has not been tampered with (the releases are signed by various members of the Node project). |
|
@tianon do you think it would be worthwhile to add a step to remove the keys we add? |
yosifkit
commented
Aug 21, 2019
|
Most of our images use a temporary |
codebytere commentedDec 13, 2018
Adds my GPG keys to node.keys
shelley.vohr@gmail.com
B9E2F5981AA6E0CD28160D9FF13993A75599653C
/cc @MylesBorins