Sign and verify manifests in Go with OpenPGP instead of running gpg (closes #181)
check / check (push) Waiting to run
check / check (push) Waiting to run
mfer ran the gpg binary to sign, export keys and verify, so signing and loading signed manifests failed wherever gpg is missing. It now uses github.com/ProtonMail/go-crypto/openpgp. --sign-key and MFER_SIGN_KEY name a file holding one OpenPGP secret key; a protected key's passphrase comes from MFER_SIGN_KEY_PASSPHRASE or a prompt on the terminal, and is checked before any file is read. Verification keeps the rules of the --require-signature fix: one primary key in the embedded block, counted from its packets so that keys the library skips count too, exactly one signature, made by that key or one of its subkeys, and signer equal to its fingerprint. An armored key or signature must be one block and nothing else. Model: opus-5-5
This commit is contained in:
@@ -3,6 +3,8 @@ module sneak.berlin/go/mfer
|
||||
go 1.27.1
|
||||
|
||||
require (
|
||||
github.com/ProtonMail/go-crypto v1.5.2
|
||||
github.com/creack/pty v1.1.25-0.20260601142114-9246436fffe8
|
||||
github.com/davecgh/go-spew v1.1.1
|
||||
github.com/dustin/go-humanize v1.1.0
|
||||
github.com/klauspost/compress v1.20.1
|
||||
@@ -15,6 +17,7 @@ require (
|
||||
)
|
||||
|
||||
require (
|
||||
github.com/cloudflare/circl v1.6.3 // indirect
|
||||
github.com/klauspost/cpuid/v2 v2.4.0 // indirect
|
||||
github.com/minio/sha256-simd v1.0.1 // indirect
|
||||
github.com/mr-tron/base58 v1.3.0 // indirect
|
||||
|
||||
Reference in New Issue
Block a user