-
Notifications
You must be signed in to change notification settings - Fork 2.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sign RPM packages #1384
Comments
Yes, we're working on it, but it may need some more time. |
Has any progress been made? It has been over a year since the last update. Is there something that would help implement? The referenced PR was closed for inactivity |
@darkhonor sorry for waiting |
Would like to implement trivy in a RedHat context but lack of GPG-key and a signed install-RPM makes it a non-starter unfortunately. Any progress? Estimated date when this could be available? Regardless, TIA! :-) |
Reopened as we reverted #3612. |
Description
https://aquasecurity.github.io/trivy-repo/ describes setting up RHEL/CentOS repos with
gpgcheck=0
. For security reasons this is not a good practice. The repo cannot be browsed as it's hosted on github pages.Can you please provide a URL to the GPG key?
Thanks!
The text was updated successfully, but these errors were encountered: