-
feat(mirror): verify repository OpenPGP signatures
Some checks failedGo package / build (push) Has been cancelledreleased this
2026-09-01 18:29:37 -05:00 | 1 commits to main since this release- Reject RPM, Debian, and Arch metadata that fails the configured signature policy before trusting its checksums or package paths.
- Preserve the last verified repository generation when signed metadata rotates inconsistently or required files remain unavailable.
- Let operators pin signer keyrings or retrieve unknown issuers from configured keyservers, including archived GnuPG v1 RSA signatures.
- Gate cached server entry points and package misses until a crawl completes under the active signature policy.
Downloads
-
Source code (ZIP)
1 download
-
Source code (TAR.GZ)
1 download