-
Notifications
You must be signed in to change notification settings - Fork 178
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: specify image name in policy.json #176
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
There was talk on the discord about not being able to pull in images with podman because the signing policy included *every* image inside of the user's ghcr account. Which means that images not signed with the same key won't be able to be pulled down
xynydev
approved these changes
Oct 6, 2023
elgabo86
referenced
this pull request
in elgabo86/gablue
Oct 6, 2023
fix: specify image name in policy.json (#176)
zelikos
referenced
this pull request
in zelikos/zeliblue
Oct 6, 2023
There was talk on the discord about not being able to pull in images with podman because the signing policy included *every* image inside of the user's ghcr account. Which means that images not signed with the same key won't be able to be pulled down
tulilirockz
added a commit
to tulilirockz/Malachite
that referenced
this pull request
Oct 6, 2023
fix: specify image name in policy.json (blue-build#176)
c0deplayer
pushed a commit
to c0deplayer/silverflow-old
that referenced
this pull request
Oct 7, 2023
There was talk on the discord about not being able to pull in images with podman because the signing policy included *every* image inside of the user's ghcr account. Which means that images not signed with the same key won't be able to be pulled down
c0deplayer
pushed a commit
to c0deplayer/silverflow-old
that referenced
this pull request
Oct 8, 2023
There was talk on the discord about not being able to pull in images with podman because the signing policy included *every* image inside of the user's ghcr account. Which means that images not signed with the same key won't be able to be pulled down
tunix
added a commit
to tunix/penguix-via-startingpoint
that referenced
this pull request
Oct 22, 2023
* template: fix: specify image name in policy.json (blue-build#176) chore: rm deprecated fonts bling from recipe fix: ublue-update failure when signing image docs: yaml not yml, directions qualifier docs: correct title casing in style guide docs: grammar recommendations docs: chore: remove ":" from Example configuration this change should be propagated to bling docs: how to refer to modules in module READMEs docs: module working directory, style guides chore(ci): Maximize build space (blue-build#165)
DocKDE
pushed a commit
to DocKDE/bluejay-old
that referenced
this pull request
Nov 2, 2023
There was talk on the discord about not being able to pull in images with podman because the signing policy included *every* image inside of the user's ghcr account. Which means that images not signed with the same key won't be able to be pulled down
RoyalOughtness
referenced
this pull request
in secureblue/secureblue
Nov 27, 2023
There was talk on the discord about not being able to pull in images with podman because the signing policy included *every* image inside of the user's ghcr account. Which means that images not signed with the same key won't be able to be pulled down
xynydev
referenced
this pull request
in xynydev/linuXYZ
Dec 17, 2023
* fix: accommodate new justfile organization * fix: remove image-info.json from base image if it exists (#162) * fix: remove image-info.json from base image if it exists This just makes it so if the user forgets to run the signing script and somehow installs `ublue-update`, `ublue-update` won't try to rebase them to the base image they chose * docs: clearer comment for image-info remove line --------- Co-authored-by: xyny <[email protected]> * chore(ci): Maximize build space (#165) * docs: module working directory, style guides * docs: how to refer to modules in module READMEs * docs: chore: remove ":" from Example configuration this change should be propagated to bling * docs: grammar recommendations * docs: correct title casing in style guide * docs: yaml not yml, directions qualifier * fix: ublue-update failure when signing image * chore: rm deprecated fonts bling from recipe * fix: specify image name in policy.json (#176) There was talk on the discord about not being able to pull in images with podman because the signing policy included *every* image inside of the user's ghcr account. Which means that images not signed with the same key won't be able to be pulled down * chore: update bling list (#181) * chore: update bling list * Review comments * docs (README): run 'rpm-ostree rebase' without sudo (#183) * build(deps): bump ASzc/change-string-case-action from 5 to 6 (#178) Bumps [ASzc/change-string-case-action](https://github.com/aszc/change-string-case-action) from 5 to 6. - [Release notes](https://github.com/aszc/change-string-case-action/releases) - [Commits](ASzc/change-string-case-action@v5...v6) --- updated-dependencies: - dependency-name: ASzc/change-string-case-action dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore: Bump to Fedora 39 (#186) * Bump release-iso workflow to Fedora 39 * Pin isogenerator version It is recommended in order to avoid some unexpected changes to the maintainer. * Update other recipe & containerfile to reflect Fedora 39 change * chore(ci): Build at 16:30 UTC (#187) Nvidia images are now being built at 15:30 UTC. Startingpoint images should be built one hour after that. * build(deps): bump mikefarah/yq from 4.35.1 to 4.40.1 (#189) Bumps [mikefarah/yq](https://github.com/mikefarah/yq) from 4.35.1 to 4.40.1. - [Release notes](https://github.com/mikefarah/yq/releases) - [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt) - [Commits](mikefarah/yq@v4.35.1...v4.40.1) --- updated-dependencies: - dependency-name: mikefarah/yq dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump sigstore/cosign-installer from 3.1.2 to 3.2.0 (#188) Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.1.2 to 3.2.0. - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@v3.1.2...v3.2.0) --- updated-dependencies: - dependency-name: sigstore/cosign-installer dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump mikefarah/yq from 4.40.1 to 4.40.2 (#192) Bumps [mikefarah/yq](https://github.com/mikefarah/yq) from 4.40.1 to 4.40.2. - [Release notes](https://github.com/mikefarah/yq/releases) - [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt) - [Commits](mikefarah/yq@v4.40.1...v4.40.2) --- updated-dependencies: - dependency-name: mikefarah/yq dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat: delete all previous ISOs when re-releasing (#185) * fix: use -R flag to select repo on iso-deleting `gh` commands * feat: add just syntax checker (#194) * feat: add just syntax checker * fix: create empty file to pass just syntax check * fix: use relative path to pass just syntax check * fix: justfiles cannot be empty to pass the syntax check * fix: format justfiles * docs: 100-bling.just explain purpose --------- Co-authored-by: xyny <[email protected]> * fix: typo (#199) * build(deps): bump mikefarah/yq from 4.40.2 to 4.40.3 (#200) Bumps [mikefarah/yq](https://github.com/mikefarah/yq) from 4.40.2 to 4.40.3. - [Release notes](https://github.com/mikefarah/yq/releases) - [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt) - [Commits](mikefarah/yq@v4.40.2...v4.40.3) --- updated-dependencies: - dependency-name: mikefarah/yq dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Fix: release-iso.yml to not fail if no images are returned (#202) Builds started failing once #195 was merged. This fixed the release-iso workflow for me. * build(deps): bump mikefarah/yq from 4.40.3 to 4.40.4 (#201) Bumps [mikefarah/yq](https://github.com/mikefarah/yq) from 4.40.3 to 4.40.4. - [Release notes](https://github.com/mikefarah/yq/releases) - [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt) - [Commits](mikefarah/yq@v4.40.3...v4.40.4) --- updated-dependencies: - dependency-name: mikefarah/yq dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix: do not format just files in CI (#205) * feat: Check that cosign.pub matches private key (#193) This avoids images which can't be updated due to `invalid signature` errors because cosign.pub doesn't match the private key actually used for signing. The error is caught early in the build process as there's no point creating an image if cosign.pub is wrong. Co-authored-by: mjs <[email protected]> --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: Kyle Gospodnetich <[email protected]> Co-authored-by: gerblesh <[email protected]> Co-authored-by: plata <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: fiftydinar <[email protected]> Co-authored-by: Lordus Kordus <[email protected]> Co-authored-by: RJ Trujillo <[email protected]> Co-authored-by: ArtikusHG <[email protected]> Co-authored-by: qoijjj <[email protected]> Co-authored-by: David Personette <[email protected]> Co-authored-by: Menno Finlay-Smits <[email protected]> Co-authored-by: mjs <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was talk on the discord about not being able to pull in images with podman because the signing policy included every image inside of the user's ghcr account. Which means that images not signed with the same key won't be able to be pulled down. This solves that issue by specifying the custom image in the policy