Sign and verify manifests in Go with OpenPGP instead of running gpg (closes #181)
check / check (push) Waiting to run

mfer ran the gpg binary to sign, export keys and verify, so signing and
loading signed manifests failed wherever gpg is missing. It now uses
github.com/ProtonMail/go-crypto/openpgp. --sign-key and MFER_SIGN_KEY
name a file holding one version 4 OpenPGP secret key; a protected key's
passphrase comes from MFER_SIGN_KEY_PASSPHRASE or a terminal prompt. gen
and freshen check that the key can sign before they read any file.
Verification keeps the rules of the --require-signature fix: one primary
key in the embedded block, counted from its packets, exactly one
signature, made by that key or a subkey, and signer equal to its
fingerprint. A DSA key is refused, and so is an armored field that is
not one well-formed block.

Model: opus-5-5
This commit is contained in:
2026-10-08 05:21:16 +00:00
committed by sneak
parent c23367c216
commit e00ec787e8
25 changed files with 1585 additions and 1178 deletions
+3
View File
@@ -3,6 +3,8 @@ module sneak.berlin/go/mfer
go 1.27.1
require (
github.com/ProtonMail/go-crypto v1.5.2
github.com/creack/pty v1.1.25-0.20260601142114-9246436fffe8
github.com/davecgh/go-spew v1.1.1
github.com/dustin/go-humanize v1.1.0
github.com/klauspost/compress v1.20.1
@@ -15,6 +17,7 @@ require (
)
require (
github.com/cloudflare/circl v1.6.3 // indirect
github.com/klauspost/cpuid/v2 v2.4.0 // indirect
github.com/minio/sha256-simd v1.0.1 // indirect
github.com/mr-tron/base58 v1.3.0 // indirect