From 4ac60afc857f79964ea2cd9cfcd0569b06e590d7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miloslav=20Trma=C4=8D?= Date: Tue, 8 Jul 2025 20:41:44 +0200 Subject: [PATCH] Update GPG keys not to use SHA-1 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sequoia-PGP does not accept SHA-1 by default; update to avoid that. Both the keys and the signatures come from c/image commit 70dbc81047f63a68130a5bdf1bfaee43db39746d . Signed-off-by: Miloslav Trmač --- cmd/skopeo/fixtures/corrupt.signature | Bin 412 -> 703 bytes cmd/skopeo/fixtures/image.signature | Bin 411 -> 701 bytes cmd/skopeo/fixtures/pubring.gpg | Bin 661 -> 1773 bytes cmd/skopeo/fixtures/secring.gpg | Bin 1325 -> 3671 bytes cmd/skopeo/fixtures/trustdb.gpg | Bin 1360 -> 1360 bytes cmd/skopeo/signing_test.go | 4 ++-- 6 files changed, 2 insertions(+), 2 deletions(-) diff --git a/cmd/skopeo/fixtures/corrupt.signature b/cmd/skopeo/fixtures/corrupt.signature index 95c29087125f0b84a7dc03ad65f2e6b2db4f996f..907e703f4456b912f4aa5968ef099f65df2308f3 100644 GIT binary patch literal 703 zcmV;w0zmzv0h_?f%)r6;(&&q~@{7C9jHeF-Br#+}u0LC?lw6cql9`;CqhwXBl$ny6 zSCUy$31X+@CugS?=@zA?r52^;C8sJ`DV3xamt^Lp>*prsWu^hyO0_ylnYoGSsYvQ! za=Iy*=^!OmO2rw8My6&~Mg~b~Muw>=CZ^^|#+C*aMwZDbNvWyH7Uq_wiRMYEiH2rI zW|o$QX(@?j2F9rdDF%i~CaLCWW(Fok=BcKpAj?WB3qbBjEXmK!OjbzF&nrpH%u6j& zD9%jJODriZN(Cv(FDS{(&x3d=%Tu+^+Ad77lsV z{X$oE#caVMf8)~fCSx%Zeu<-k6U}nm^=ABj|K4P0#gA!5?Xh#XIV+82N?yHvZhP1F zgP!VN8=tql`8N}IUWfh5sxb4hN#n*a>G#Xj zJ=z@a##S0jtM$oUnz=GOMEKcasjpj~2vxQGy#Df2U;Ua}&5sO!cB!Oru6W%d#DAxE zxzfXV*U!gBS;*aa$SzhB|9IoZeGSDu*WA1e`m1iICO`eR^wzb;J#G7TPE|+}a<1@B znzKbs>A{SnoEBGow}fz~amv{)-1E*#rA*bUf8F0ZcRpXuyzCpIe;^4inj@#5c z`@6S(Vd`K$x^<4tgBzJ2nO?}PTPboy_V}(NbJqM;OaD_FwdCEO1HGQ6Qy(2onbY}Z lqEh~!zb;oE-kI8aaT#B{y;R1hNop$PhdkY1SnT)%018yfZz})* literal 412 zcmV;N0b~B70h_?f%)r5TyXccd_m-R!jHeF-Br$}&`th(@DY+=KBr`cNN6D&MDKjNC zuOzdi62wl)PtHy)(k)6&OD#&xOHNg?QYuL;F3HSG*UwGN%S;2Zm1=dAGIJBtQ<2oe z}j0{s#Oiay_j4cf;j4YE=l2TKXEzB)V6U~!S6AjIb z%q%Sp(^3-642)9^QVa}}Oj6C$%nVG7%u`KGL6((N7J%H5SdyQcnXHhUpI4HYnU`9m zP@I{bmsnC-lnPRmUr>^np9k?!a#1Q!aS=j~63~#$T%f}ea|@KL3{6ZejEpVK4UKDS zJLa%3Fmf=ku`+?eg@KDx02W$NSD63DeycibxIdt0URPzmL;uWzVE5D4c7)8*<(8R~ zSn@1YEb+oJ!Kl77mX)6yrv!YrV9zQ$mmANnr}X;z%NDZ?-VUoWIyq-Ti3+v#79^%&%*SuC7PcG4elSu2almYHV9wlEtw+YEQ+i Gxc~}fWX4wj diff --git a/cmd/skopeo/fixtures/image.signature b/cmd/skopeo/fixtures/image.signature index f89272127575245341ca24b85edd44d8f4f215ef..86f17917ca15710c76054ba1387f7553953b59dc 100644 GIT binary patch literal 701 zcmV;u0z&Y*RGSh%;rCJ@O%-qEER3!B< zIo*`ZbdVA&rQ(c4BU3XgBZH(gBg51b6I1gfV@m@IBg^EJq}0@83v)};MDwK7L_;$p zGfPXuw3I|M1LIVK6a&K~lT`CGGXoPN^Hft)kYy#61t51MmgMJVCMzW8=anR8=A{-X z6lbRAC6<&HrGgaY7nEe?=RrJ_T$Bn_T!hf01T-Ww7wE9W+yW&lLlaXABV$W*L*v@o zPR7kF42&EMvSNxX9B0*@xIKCqbJui9rV{u zTGc$8zmVrLzgb^hlyjrA^tF4Jf6NR{{up-WtVRC%j|T6}_xNc1JHG4324mKU$tTi- zH>vBF_IQf1b_N7YQ=HSk>hI$RG2u7XA7I@7Yu_B6;`;Sdlcc6j+4%B@^wa52_-!SY zw3$Us`Q{cK#pUtUxA}t4zSTeHO5gjomD|&buTJ>-lk4BL^W0`J%rERLEz5J^2>3I3 zR<1Tj-p!8a$qRZ@EnIFtFFuyb(xUyh?EH?B-7^pGRd1Tj?xnHHZHvji&#lHC4v#-% zKFk%o5L`MTx>e0wzI@`j*TsRd#?M-PVvE@(N`{oq3zSsQ_qcpR=A(VQSKyRgtsaMY z!#*zTnYl)4!I2r|GyNBaDk&IFZ&^9(+x4I`vRM-&k0^iKHM4!Wm-nTA-X`8J4>=q= zc{Qk#{itq8#q`Zl5(RnZl8;Be`;-v%%$?07eoDaJ+upZ7&b}a<^*`=9-=wzpnrjw2 jS7g@zWc3n|{ClpI<6-sZK*7IT+YPwni~NCoiS~w literal 411 zcmV;M0c8H80h_?f%)r5TyXccd_m-R!jHeF-Br$}&`th(@DY+=KBr`cNN6D&MDKjNC zuOzdi62wl)PtHy)(k)6&OD#&xOHNg?QYuL;F3HSG*UwGN%S;2Zm1=dAGIJBtQ<2oe z}j0{s#Oiay_j4cf;j4YE=l2TKXEzB)V6U~!S6AjIb z%q%Sp(^3-642)9^QVa}}Oj6C$%nVG7%u`KGL6((N7J%H5SdyQcnXHhUpI4HYnU`9m zP@I{bmsnC-lnPRmUr>^np9k?!a#1Q!aS=j~63~#$T%f}ea|@KL3{6ZejEpVK4UKDS zJLa%3Fmf=ku`+?eg@KDx02W$NSD63DeycibxIdt0URPzmL;uWzVE5D4c7)8*<(8R~ zSn@1YEb+oJ!Kl77mX)6yrv!YrV9zQ$mmANnr}X;z%NDZ?-VUoWIyq-Ti3+v#79^%&%*SuC7PcG4elSu2an1YHV9wlEtw+YEQ+i Fxd5g!#>fBw diff --git a/cmd/skopeo/fixtures/pubring.gpg b/cmd/skopeo/fixtures/pubring.gpg index 2d922b42d8820a545a3326e3d6c9268ea68f1743..e1e907ad39b99b0e9bda9f216a5e67b74a45d9e4 100644 GIT binary patch literal 1773 zcmajeX*?SU8prV*ZpKkJp^i$G&>~V=9jjWQl~N@csrv|1EpgOYS9C~k4<<%3;fTtg_|l5tfDReqZ%3EMTLIF~ zwa#PRW^=1iXCHnKSjZ^;+Hpm)SzINHKlS+0j(yHG(=5|0&ttllgQs?*AKn_Y!ThVC z>*$?Z;Scm_Cd%zNg7oZDm&1w&<^p>&ztr3nz6Qesa@+5~o?#Z_=SK09&z;I7{o^$) zGV2y>l~T{bl@}h|>}460dsB1j0*kRh>~r(}^X{XkwX&S8vp3~=1~>x!4y6XdCbfTy zy}Zt|lOQWLj2SRZFwUn&g{`elH6hs!=xZM%h4>u z<>eGvD&=Q{gb9iVYo6m|ScM6@%k-bAHpR#fLP5FGj$$Rw`?GPQt!1sgx6vep$d43{ z9=zx;V`fGG86W^yD**rm-~)hwKd#|ecu)x5KSU$KKRn{c-~f#v|Cs+3p#K&m;D~@M zPy}#ZK~q3v5IS$eU2?K(q6;n=Z(r5^GG#3Y`pEOWp+YaWPr=kY=tW{b`(`ctbs~;Wf<=vlk>wdCYp#nOxvT&>- zoEW)FEZB=$vKLa>(5_vceXFlF-MgYKx@E}hPU}p5(JxIs8;gShYQ_())85k7hPQeD zXol#zLkaR`8+$At)n^}?#dMq6V4FtkmU#{7L+P21+S05`>~%B=4D&jn&Ag{QHI2Qv zZ7Q7OL!r-AvFa_;_v(27FY~S2?LIFiS)m>P&T)4JeEChVDK<&H0TOE|ipb>f;5Ub%-w#Y1e%H-PU5gl9T0% zMO*Z$;O@D~CGd^({QdrHn@Y=&q?p2_PNf-VXbol`3W0RO%LK+FGavVS3MyTTC$ zKeCFF#;TxOVoPNcTW%H!E1zP!=)KlBL1>*?Q1!2nLpg*y>T_;IDp&YB1c7CTgC=R2 zq>n#DwBPsEz2}i!C4yXK-Zo1}=7yHN(vxXLf5IGM#rLb)z}bweyHe9P>Ckyk$|_$~ zOT#s>Y_$>7*3DkIuxIIBTGStF(0O;_QbT0)L!6NNjT$+Q4kdGlo9W5kN)3eb>hU2j zqG$ydL4K@9QeeWwSY#a)5ejrUy-ygcHh>vJ63qI9#<3@M`N6X- zjpwiZprZC3T`7BN^89^AjT6nUQEG8@aSki#V1Oy%J4K?Sj}>h|^ZH$;o8i-l%%6N~ zW1t%`iO12M14vJ--1Bmm^b(4lZL}3LySLH;F;kWXb7VMzLPT3UCdR4 zCj;mu>k@kXHI6qfRS;}j9?yrxa;#%-hEr;KmL^oFT4kxBQC?CpfO%Xq|7e%UYhjkV?!UEsA z*UU1~cJxw)2J#G%XmLIj>}UZJOLK7U_4a!r&9eN&_!=wK%S9!S<$Zf-s=l%N)dOBr z$K@Jq?~3w73?!Ky5L(cH66S5~oem$o7gIH()MmNIMdL)5ehO|*|H{!)_is{2YN?)+ zzA4iv6_F<>mkO|aMQiZ?K+p(~4i!q7C^teAS9Y#o{j^|3m*Vb~3J`EU@ylf0Uo*%p z8(yz%yxbaP#oWeNXj|g!&t*3?DayuViSh~+c%RK1qoN?-4af-%4ri!J+n~2`=)f%) zBC!1Qqu)FUmKA#7cr?#oZXbH5Jw82^JA?nMlo~aCj%jgnq&>#j)?dXRtzq>isDA_0 C^F#Fj literal 661 zcmbQy%M$kL^GZe*hP|&QMD5T{72K*imACUkzy({`%eI@AY^z|MztYiXox{)iSG+$q zcyIYLOL$_h4zGS}-*XveGvCKHU1s$ahrhlRTl~7o`$LA)sig0RY8RV*`y0Ek#NFFU z-bu>k^Sj3r%)M&759RT#J^wd-|CM9clr=SMk35^)8T?s|ZT{299qJ9541$adj9Y|? zv-1m5^A$=`i%T-|(iO5(D?4_u2s1JC9X zB*(}k-oU`cDR8^!lSKEHoD*W_SQr+lM0D|mmJ8j_fn<>D(vsG=9xR#K0>!I2Y+O~5QBtAF&dhy;|)a1f~qwHsd z%tbbRRD61-^iJ*thjIgpHQS9BhUn6T%0`4%Zoi{~#gR`Z#{ygU2JqvqRtMWPR+PeAIAO5#IYbN$ZcpcLVf4k-F sw5pE90-7ApR_-aRIk0x^_4;q+VKxyyOO~6x{jGN`CCfdyv=J0$0QSHl5C8xG diff --git a/cmd/skopeo/fixtures/secring.gpg b/cmd/skopeo/fixtures/secring.gpg index 36cf0f7db274dd9b56ba91c194d5350734e08428..bb460cb6d5e285eaecf6230e79d271e329b548b5 100644 GIT binary patch literal 3671 zcmV-d4yf^!1y}@VS*U#h3;@1ss$wTkFn6zgT_r5m%|()ju6tUaju(jaNJ10#15dV2 za&ipT7Dwz(;>Dw#2>XY^rr{URm&>RguUqc}@rsBJuU9#aa)3v#^6wRQ@Q&QGh!afh zu)PJ|(G~sJ(Ty}VriJwo7XxR$5eN4FMb^3i5UnCRT3q0isZBSJJ^% zk@el6koQcJPBoD=kzW!hKg}umc#mq$MpwtQ!~fG;K0F=FLEUZ`Oec{w_*{xEc4rP5IJdLsCNEn7UG#TZJTgbL8qhXnov1puH zYtlO8W#nDdFCvjtLz3_n@-1e9q-~e39MXxs_IgF`@<|Mi7q^p}$$s(}U!+4E;%{ym z#2dxf$jeax3Hc)xF;d*%|3Zlr=f$Wqm~N3!IE+=n-Hs1~qBaaOP4XvjC@6>;y~2^j4gs&A$#Gg=3J^Ue3R-3utyt8`ENlLHrkowkMLqC zn!H~G!KVD~OB%%+jFZ7TYVn}WHnQ#>HMz(YF2T>zIBsj2a0zk`4~57h+us8nIMs;A zP%Xx>Cg;|#wV6S;DYFUFed#OqU?6f2LoO~e{`!bq+v_td0$uq4k}Ja^5m+mZqhr~f zbzJChM~SYP4A*xEd^Wx=_3$DD_&H_E-lnALwrOp>;ol{`YSaE~^7MpAP0x=BF-ro$ zF6&|CUKvqR$agb}>HTLi3{Bdv59yO$UeSH9)k%qwDfYQmpYKHGLx<+ZYyZ;O5dR)f zMFw*3%eWm7=_Fx$Ph?9I9POjhUH;HU=_3v6r5j6tFLN-2_|`CxI(9`j2&?6DUM=`lRb0r1<)l}EQuV(w*tB&t%+3IDG8ADx`Rv(X^eKl@>cmJQxEIgDs z5@pyo+WSS9-iD96n^}N$4hD`YMfuX~S?AExSPVf%3SbIra&&d~-*SZ?PQpu}jTZ|| zDPP0H!Wn_pLnmyc1Z&x(xpD+pbk^MMQ@Cha@ns#K7eL8k2ME?o`H%(xlVQz(2Y!aG z3JvYJx4^*#eSf(Uc83&^Zo{v{m$WuATSwQN4HbKNiM#-Z2n@r3Q>dY_x@hy@h$kX9 z1_0!Nxm`u&U#sIt%n()jWR{34O%eAZ8UDLs4$m>II=nSEN{shQ|COgBDIMvaB)ENCN3EijY{Qu9FqyN!fJ~|R>I`XVW%!OWY-1$Hl8!Ng`TUv@kaiW z%MOYO--P`RbWeUjs;Ywa@kq&W-E!orRSTw}EYw>?UlMGN#}|!!MqgeqsR<^kd*jr! z5-@>b$t|rHZ?<{`bz_<92|fZ^?Ox5}@qZ$Hb8y`;ZLuoKb zQ9JP<{6daTMprhDomG!}fyCOVD&?_4{T>#eWl6@aI+%Tt`J10R@&d@F<1PNcDYZUU zS8r{v04vvT!;EER?5HwQkHrZN;POVf)>E_+b8ByKWp5yKWpi|CZf78CWqFAK(F79# z2mm`4Ap{7`Cgeuq=~79zqy_0R^h+b?-9rTeXj!Oz0viJb3ke7Z0sfq2T9p1?6BMI>?uf&JHfwIdGnKyc7EC8<7 z{ZXCJo$b%`@<6y8C|xFk6*%wuwqhHs+PDfRx4bOyG44N=w2RJ*jgY*DL!L|}A%dtm zu?Fy!tHrLh$Y%7JG~8mBq~WKwvp#Ip8&>Mz&9h>NaIpwK zv0AFsA@B8p@DTwg*I<}u=-C}Z{T|M+-7u-cMgozx$)sJ(nUnm8a|VEaDce0_?i^!B zM@hI*)A8rC7*ap$JiK`91^GIr=>t=Xmix<+My5Y+fO(pLza~Z?n;?{#pzBr@RA_ zs7v_|-dm(5{9oJT-6Dip{gis(PxW-K#d$D^@>x%;bHG&Nnh)`ld zoy;Lob+245t8|TpW3YK9?|FY8R=>$FQ<mHLb?YYv4t~tmiMWwvbFPZb>n422W?<-P zU~1iwrlH}*>0AFdxW$9}%|WT^N<75ApieTrjYgcKuYD9*8WBI`UR&QbSrM-i~2cRnGa`qi=2HG@Ok(@)F@0g_ligJDheQ8+D!LY+a#G}v$A|4?3R4VAO%!|E#SB0QOB|4g@UIn$Gfq zQxmPBff-0{LU`>o9c_EmIso!P?8C}W;D9WBO?5b*F*No$+V>B?K*(wLD}In{qRc6l)FcPnol>#43%(z>J`zwNcIejPwl3+ozFL zlpy#X|4VeMHZ9vM>Br`|%D#Om7aFKaa|Qos2vG^g4F2T?(zB|QyWI8@IWuOUUanF{ ztvh|1gll7mnOb?!*MTS`I5`4mzSo_-aP5GKkx&*$a90`|t~s17g(VZ3h)}f({>wD7 z-$6H}&Sefa6x^R-m#?6J$1RWQX?)T|m+ydQ`O+xS32F$gv4T$0l)uc1IFMBzn^1^% zz3}gFSm{4$!O7B9lc*o?R1(nLoUo+%;WtFGi+_Y$3>>2=Lvr}ZVWAwkybbjt2K@Nk zDodO(q3Eo`fV?^10Eq#%1Q-Db03a421PIM0yn2@vTr^h+b?-9rgk3;%e${o%FXFPJKdaN8V_8k+-@^r@G%cFE5g-K69k|4GH7AWc4jX#lGW8@T zUc8+5i8ilQ&bj_RGkCS9$j^Ucv$cB*QC%X5lMJ|LMg14@a4wDpD&ouQ7%;l?4=r z06)T=v}M|YAZHM927}n6F;W(P*jE=eQV8%vZT(uJl zT-CN#NQmH~p<5xB88VIxqoo=&%0|gCn`;4693&vz+|H*XEy%Ub{akJw1nR5XWaNn~ pk#YS{|KzBz^!{OopfBB&-*Dy_hIigNuRJHwy?InfWg2BxAVHa*^A-RA literal 1325 zcmV+|1=9MJ0oVjq>hq}q1OUD2kXpDaWf8R{l?{o|P|!Uc(>=1Jws-}fsX2^_ z4fwE2wEUVAk&P@3FI|r390N8@<2;Hse|W?7?G~f!f=lpdLds(I!hNGQ_WfOL^X}u2H%fdOmNU!X%tQ<$bc*q|40Egb1Igsfi{2?M}wiUfaS1WRqe*@a`sDu0)qX% zmUDY2#OvRC&YzJYaSUn5cYqevqeomDMN0)I65gO2%>|jK_hE)r`1EUH50xnzjGSQ3 zep63hUy60oF_BzEjbe!-8?qw!b4oNZ@X!Xx5% zXy_2FDSaN^9WmvOCH|27rkRs=-|{Rbd$6lHZV1^C0nNZ~0s!e@=<~WT_ngHa(M*DW z<(S4GE@uu`kF2=Jyx5__8p=|h%u~YX_J$0B1lGXEdWH&5cIQY3%K)FdOPK$pS-og+H|NHUnkmxTQG!DKJAo5yh6(zxTmXkLCcp5T@|xHr%7bdiCR!UKNFr6ZwN4ChKMM5k&Npb#1O$xpG2 zbMIzOQo81E=b$*{umS)8odMVcR_gPq0R#ZZ3;#l}2~L?13%P|Rk{2oxJB7l1@GCu? zAQ4P<{nVTo$g~@2!5Gv)8j;Xuy(the7-6U)VjFq>3)sv<7K` zHY0rt*UIprVE@!WXYT2+%r>;N+0`y>y2ly-(0(E&0PyW8X4y_~T}gec@nK4x)2(~< zvj#YS-0G@ia=v!H|t5~K?_(!@&dcH>~Zofu&P0LY_}Go-=2=87?8)!Z=iJ_2#_ zm%RLP7t5Q8Pbb&JS(Hj5kZQ`eo7v9=M@lAg)ru@Gizzjv zg)^e!P2=GL0OBIl)QcIO<~UT(dTc!~4}i8s2CmIHs~185vcC={MLw<;Pw^K9Vara( z`8LSbO(t#m6gdjp3+W1%-D%+9(4e-6p9B~I0ssjG0#@qtsRA1e0162Z+j8<4i?nRW z)XM|_t4C**N<%d&3r)&RTIFvY4&45!rxS$oi6Y`gATq(x76YgZizrl5=Pnw-Auv<* zS$$+s+yJeflpC-^IZH2|1N)4jjjJUNLb|oH`uq>=46KokSW3n&SM9XzmU@Vz5Ge@e jsl0J~z^$#b%9HOF})z2nVFH5k%@sJBR9EmqM`Uk_4h0s3=p6=`5cQ80L(!NFaQ7m delta 60 zcmcb>b%9HOF})z2nVFH5k%@sJ?A7O$6Ai^Ts=sI9U}FFS#mVPb6ojB0h!B_r0II+W AUjP6A diff --git a/cmd/skopeo/signing_test.go b/cmd/skopeo/signing_test.go index ba16b82e..b905facc 100644 --- a/cmd/skopeo/signing_test.go +++ b/cmd/skopeo/signing_test.go @@ -16,9 +16,9 @@ const ( // fixturesTestImageManifestDigest is the Docker manifest digest of "image.manifest.json" fixturesTestImageManifestDigest = digest.Digest("sha256:20bf21ed457b390829cdbeec8795a7bea1626991fda603e0d01b4e7f60427e55") // fixturesTestKeyFingerprint is the fingerprint of the private key. - fixturesTestKeyFingerprint = "1D8230F6CDB6A06716E414C1DB72F2188BB46CC8" + fixturesTestKeyFingerprint = "08CD26E446E2E95249B7A405E932F44B23E8DD43" // fixturesTestKeyFingerprint is the key ID of the private key. - fixturesTestKeyShortID = "DB72F2188BB46CC8" + fixturesTestKeyShortID = "E932F44B23E8DD43" ) // Test that results of runSkopeo failed with nothing on stdout, and substring