Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature request: Verify upstream GPG signature #29

Closed
alexhaydock opened this issue Apr 27, 2020 · 2 comments
Closed

Feature request: Verify upstream GPG signature #29

alexhaydock opened this issue Apr 27, 2020 · 2 comments
Labels
enhancement New feature or request

Comments

@alexhaydock
Copy link

Looking at the Snapcraft.yaml file, it doesn't look like there's any verification going on here for the fetched .deb file. For a security-focused application (or really any application) I think it would be a good idea if we verify the deb package as it gets pulled into the Snap build.

Does it make sense to include a gpg --verify step in the override-build: section?

Signing keys: https://updates.signal.org/desktop/apt/keys.asc

@alexhaydock
Copy link
Author

Actually, doing this is a bit more complex than I thought so I posted a forum thread here with some suggestions.

@merlijn-sebrechts merlijn-sebrechts added the enhancement New feature or request label Jun 14, 2021
@jnsgruk
Copy link
Member

jnsgruk commented Aug 1, 2024

Hi - this isn't really relevant anymore, since we're building the application from source, so you're able to check exactly what's being built. Closing for now, thank you!

@jnsgruk jnsgruk closed this as completed Aug 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants