Mail archive
alpine-devel

[alpine-devel] APK Packages Missing Signatures

From: Ladar Levison <ladar_at_lavabit.com>
Date: Mon, 4 Jun 2018 20:53:31 -0500

It seems several packages have made it out to the mirrors without
signatures. It doesn't appear to be every package. The following are the
ones I know about:

ERROR: busybox-1.27.2-r10: UNTRUSTED signature
ERROR: ssl_client-1.27.2-r10: UNTRUSTED signature
ERROR: busybox-suid-1.27.2-r10: UNTRUSTED signature

And if you run:

curl --silent
https://dl-3.alpinelinux.org/alpine/v3.7/main/x86_64/busybox-1.27.2-r10.apk
| gunzip | tar --list

Note lack of an SIGN.RSA file. (I'm assuming that is the file which is
supposed to hold the signature.)

L~





---
Unsubscribe:  alpine-devel+unsubscribe_at_lists.alpinelinux.org
Help:         alpine-devel+help_at_lists.alpinelinux.org
---
Received on Mon Jun 04 2018 - 20:53:31 GMT