Skip to content

Centralize all key fetching logic#2015

Open
inteon wants to merge 1 commit intochainguard-dev:mainfrom
inteon:keyring_package
Open

Centralize all key fetching logic#2015
inteon wants to merge 1 commit intochainguard-dev:mainfrom
inteon:keyring_package

Conversation

@inteon
Copy link

@inteon inteon commented Jan 13, 2026

Introduces new chainguard.dev/apko/pkg/apk/apk/keyring package, centralizing all key fetching logic.

NOTE: when producing the lock file, we now also download all keys; this allows us to deduplicate these keys, we might want to include key hashes in the lock files in the future

@inteon inteon force-pushed the keyring_package branch 3 times, most recently from adb3c10 to 193a8af Compare January 13, 2026 21:15
@inteon inteon marked this pull request as ready for review January 13, 2026 21:16
@inteon
Copy link
Author

inteon commented Jan 13, 2026

@markusthoemmes could you make CI run on this PR?

What do you think about the general direction of this PR?

@inteon inteon force-pushed the keyring_package branch from 193a8af to cc540b7 Compare March 4, 2026 13:26
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
@inteon inteon force-pushed the keyring_package branch from cc540b7 to a9f172e Compare March 4, 2026 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant