PWAsForFirefox 2.16.0 #740
filips123
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
News
There are now GPG signatures available for DEB and RPM packages. This should allow users to verify the origin of packages. This should also fix a warning displayed by some Linux software stores, such as KDE Discover.
Packages are signed automatically on GitHub Actions by the GPG key
F17A EF1C 8C47 5B51 B5F3 03C6 912A D9BE 47FE B404
, available on Ubuntu Keyserver and Packagecloud. This is a PWAsForFirefox-specific subkey of my main GPG key7440 07D7 10DD C8E2 0673 F545 2D15 DC76 BD6B 710C
, available on Ubuntu Keyserver and GitHub.Signing for DEB packages is done using
debsigs
and may be verified usingdebsig-verify
. Signing for RPM packages is done usingrpm --addsign
and may be verified usingrpm --checksig
.Repository metadata are still be signed by packagecloud.io.
As a reminder, MSI and RPM packages are signed with a code signing certificate provided by the SignPath Foundation, and all built artifacts are attested using GitHub Artifact Attestations.
Added
Changed
Fixed
This discussion was created from the release PWAsForFirefox 2.16.0.
Beta Was this translation helpful? Give feedback.
All reactions