Files
shater/dist/shater-feed.pub
T
omarandClaude Opus 4.8 b4b7324db6
build / aarch64_cortex-a53 (push) Successful in 3m16s
build / x86_64 (push) Successful in 3m3s
build / release (push) Successful in 27s
feat(ci): sign the opkg feed with usign (key 5ac4b177689cb8e0)
The published feed is now usign-signed, so routers keep opkg's signature
verification ON instead of needing --no-check-signature.

- ci/install-usign.sh builds the standalone usign on the runner (the index steps
  run on the bare runner, not in the SDK container).
- ci/make-index.sh signs Packages -> Packages.sig with the secret key from the
  Gitea repo secret KEY_BUILD; it now FAILS the build if KEY_BUILD is set but
  usign is missing/broken, rather than silently shipping an unsigned feed.
- build.yml installs usign in both the per-arch build and the combined-index
  release step, passes KEY_BUILD to the release step, and publishes the public
  key (dist/shater-feed.pub) as the release asset shater-feed.pub.
- Setup is now: install the public key once into /etc/opkg/keys/<fingerprint>,
  then plain opkg update/install/upgrade with check_signature left on.

Verified locally on the VM: usign -S/-V round-trips, and with check_signature=1
and only the signed feed, `opkg update` + `opkg install luci-app-shater` succeed
with no --no-check-signature. FEED.md/README updated (key rotation documented).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LLthkP2S8WAfxu7fcYbPfE
2026-07-13 14:37:03 +03:00

3 lines
100 B
Plaintext

untrusted comment: shater feed signing key
RWRaxLF3aJy44JbcxSFujtrFFEQ8lIsnTkd1K5TdjIhdlC2c0wa0fv4V