Skip to content

Sync repo templates ⚙#690

Merged
yasminvalim merged 1 commit intocoreos:mainfrom
coreosbot-releng:repo-templates
Mar 9, 2026
Merged

Sync repo templates ⚙#690
yasminvalim merged 1 commit intocoreos:mainfrom
coreosbot-releng:repo-templates

Conversation

@coreosbot-releng
Copy link

@coreosbot-releng coreosbot-releng commented Mar 3, 2026

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request, created by an automated workflow, syncs changes from a template repository, including fixing a URL in the release checklist and attempting to improve the RPM signature verification logic in signing-ticket.sh. However, it introduces a weaker signature check that only verifies the presence of the Key ID in the output rather than the validity of the signature itself, which could allow an attacker to bypass the check by manipulating the filename. The accompanying grep check was made less specific, introducing a potential security issue.

@yasminvalim yasminvalim added the skip-notes This PR does not need release notes label Mar 5, 2026
Copy link
Contributor

@yasminvalim yasminvalim left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/LGTM

@yasminvalim yasminvalim merged commit 88be170 into coreos:main Mar 9, 2026
9 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-notes This PR does not need release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants