[CentOS-devel] SIGs rpm packages in testing repositories will be signed starting from next week

Thu May 11 06:44:08 UTC 2023
Fabian Arrotin <arrfab at centos.org>

Hi SIGs folks (and testing community) !

Just to inform you that next Monday (May 15th) , we'll migrate our 
sign-and-push process to a different infra/machine, but you shouldn't 
see any service disruption.

We'll also implement signing for the packages tagged to -testing, and so 
landing on https://buildlogs.centos.org.
It's a request that came through the Infra tracker 
(https://pagure.io/centos-infra/issue/1131) and that was approved by the 
CentOS Project board (all details in that ticket)

There is nothing to do at your side (it's not an opt-in scenario, it 
will be implemented for all SIGs), as it will be transparently processed 
next time you'll (un)tag-build a package (or more) to your -testing 
tags. (We can also manually process existing -testing repositories on 
demand , should there be a need/request)

You can though bump your 'release' pkg (that contains the .repo files) 
to reflect gpgcheck=1 and point to same key as for repositories going to 
the mirror network, but that's optional (SIG's choice)

I'll also update the SIG Guide (https://sigs.centos.org/guide/delivery/) 
to reflect that change.

Kind Regards,
-- 
Fabian Arrotin
The CentOS Project | https://www.centos.org
gpg key: 17F3B7A1 | @arrfab[@fosstodon.org]
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://lists.centos.org/pipermail/centos-devel/attachments/20230511/39b57674/attachment.sig>