check / check (push) Waiting to run
mfer ran the gpg binary to sign, export keys and verify, so signing and loading signed manifests failed wherever gpg is missing. It now uses github.com/ProtonMail/go-crypto/openpgp. --sign-key and MFER_SIGN_KEY name a file holding one version 4 OpenPGP secret key; a protected key's passphrase comes from MFER_SIGN_KEY_PASSPHRASE or a terminal prompt. gen and freshen check that the key can sign before they read any file. Verification keeps the rules of the --require-signature fix: one primary key in the embedded block, counted from its packets, exactly one signature, made by that key or a subkey, and signer equal to its fingerprint. A DSA key is refused, and so is an armored field that is not one well-formed block. Model: opus-5-5
32 lines
987 B
AMPL
32 lines
987 B
AMPL
module sneak.berlin/go/mfer
|
|
|
|
go 1.27.1
|
|
|
|
require (
|
|
github.com/ProtonMail/go-crypto v1.5.2
|
|
github.com/creack/pty v1.1.25-0.20260601142114-9246436fffe8
|
|
github.com/davecgh/go-spew v1.1.1
|
|
github.com/dustin/go-humanize v1.1.0
|
|
github.com/klauspost/compress v1.20.1
|
|
github.com/multiformats/go-multihash v0.2.3
|
|
github.com/spf13/afero v1.15.0
|
|
github.com/stretchr/testify v1.12.1
|
|
github.com/urfave/cli/v3 v3.14.0
|
|
golang.org/x/term v0.46.0
|
|
google.golang.org/protobuf v1.36.12
|
|
)
|
|
|
|
require (
|
|
github.com/cloudflare/circl v1.6.3 // indirect
|
|
github.com/klauspost/cpuid/v2 v2.4.0 // indirect
|
|
github.com/minio/sha256-simd v1.0.1 // indirect
|
|
github.com/mr-tron/base58 v1.3.0 // indirect
|
|
github.com/multiformats/go-varint v0.1.0 // indirect
|
|
github.com/spaolacci/murmur3 v1.1.0 // indirect
|
|
go.yaml.in/yaml/v3 v3.0.5 // indirect
|
|
golang.org/x/crypto v0.57.0 // indirect
|
|
golang.org/x/sys v0.48.0 // indirect
|
|
golang.org/x/text v0.42.0 // indirect
|
|
lukechampine.com/blake3 v1.4.1 // indirect
|
|
)
|