Skip to content

InRelease file: support Signed-By field - #1518

Merged
neolynx merged 1 commit into
aptly-dev:masterfrom
LebedevRI:inrelease-signedby
Jan 4, 2026
Merged

neolynx merged 1 commit into
aptly-dev:masterfrom
LebedevRI:inrelease-signedby

Conversation

@LebedevRI

Copy link
Copy Markdown
Contributor

https://wiki.debian.org/DebianRepository/Format#Signed-By says:

Signed-By
An optional field containing a comma separated list of
OpenPGP key fingerprints to be used for validating
the next Release file. The fingerprints must consist
only of hex digits and may not contain spaces.
The fingerprint specifies either the key the Release file
must be signed with or the key the signature key must be
a subkey of. The later match can be disabled by appending
an exclamation mark to the fingerprint.

If the field is present, a client should only accept future updates
to the repository that are signed with keys listed in the field.
The field should be ignored if the Valid-Until field is not present
or if it is expired.

For both the CLI tools and JSON, the field is taken as a string verbatim.

When specified, we must also provide Valid-Until field, and i'm not sure there is an 'infinity' value for it, so 100 years will have to do?

Fixes #1497

Description of the Change

This functionality is missing as compared to reprepro,
and i would have preferred not to have lost it when switching apt.bcachefs.org repo.
It's not terribly important, but hey, it's not like it's too intrusive to the users.

Checklist

  • unit-test added (if change is algorithm)
  • functional test added/updated (if change is functional)
  • man page updated (if applicable)
  • bash completion updated (if applicable)
  • documentation updated
  • author name in AUTHORS

https://wiki.debian.org/DebianRepository/Format#Signed-By says:
> **Signed-By**
> An optional field containing a comma separated list of
> OpenPGP key fingerprints to be used for validating
> the next Release file. The fingerprints must consist
> only of hex digits and may not contain spaces.
> The fingerprint specifies either the key the Release file
> must be signed with or the key the signature key must be
> a subkey of. The later match can be disabled by appending
> an exclamation mark to the fingerprint.
>
> If the field is present, a client should only accept future updates
> to the repository that are signed with keys listed in the field.
> The field should be ignored if the Valid-Until field is not present
> or if it is expired.

For both the CLI tools and JSON, the field is taken as a string verbatim.

When specified, we must also provide `Valid-Until` field,
and i'm not sure there is an 'infinity' value for it,
so 100 years will have to do?

Fixes #1497
@neolynx neolynx self-assigned this Dec 30, 2025
@neolynx
neolynx requested a review from a team December 30, 2025 19:14

@neolynx neolynx left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

awesome, thanks !

@neolynx
neolynx merged commit ea797f8 into aptly-dev:master Jan 4, 2026
80 checks passed
@LebedevRI
LebedevRI deleted the inrelease-signedby branch January 4, 2026 15:27
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
aptly 1.6.3

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## Changes


  * NEW FEATURES:
  * Google Cloud Storage (GCS) publish backend (aptly-dev/aptly#1550)
  * dput-compatible file upload API (aptly-dev/aptly#1436)
  * JFrog Artifactory publish backend (aptly-dev/aptly#1553)
  * AppStream (DEP-11) mirror support (aptly-dev/aptly#1543)
  * Multiple GPG keys support (aptly-dev/aptly#1479)
  * GPG key list & delete API (aptly-dev/aptly#1558)
  * Edit mirror API endpoint (aptly-dev/aptly#1535)
  * NumPackages in list responses (aptly-dev/aptly#1559)
  * Mirror latest packages (aptly-dev/aptly#1513)
  * Reproducible builds / `SOURCE_DATE_EPOCH` support (aptly-dev/aptly#1537), aptly-dev/aptly#1542)
  * `Release` file `Version` field support (aptly-dev/aptly#1533)
  * `InRelease` file `Signed-By` field support (aptly-dev/aptly#1518), aptly-dev/aptly#1519)
  * GCP / Google Artifact Registry authentication (aptly-dev/aptly#1505)
  * Update publish label & origin (aptly-dev/aptly#1484)
  * Ubuntu 26.04 / resolute builds (aptly-dev/aptly#1571)
  * BUG FIXES:
  * Race condition & concurrency fixes for the REST API (aptly-dev/aptly#1574)
  * Fix empty line in `Package-List` for source packages (aptly-dev/aptly#1588)
  * Publish: check storage exists before publishing (aptly-dev/aptly#1587)
  * S3 publish race condition (aptly-dev/aptly#1594)
  * Repo edit name optionally (aptly-dev/aptly#1593)
  * Fix crash in `aptly db recover` (aptly-dev/aptly#1565)
  * Fix deadlocks in task list (aptly-dev/aptly#1529)
  * Fix S3 re-upload issue (aptly-dev/aptly#1480)
  * Fix `aptly repo edit` API (aptly-dev/aptly#1493)
  * Fix out-of-disk-space error handling (aptly-dev/aptly#1504)
  * Fix `aptly mirror update` removing unrelated params (aptly-dev/aptly#1466)
  * Fix concurrent pool linking race condition (aptly-dev/aptly#1481)
  * Fix `dpkg`-compliant version comparison (aptly-dev/aptly#1509)
  * Fix Swagger property casing and spec errors (aptly-dev/aptly#1510), aptly-dev/aptly#1498)
  * Remove useless nil check (aptly-dev/aptly#1482)
  * Format Go code with gofmt (aptly-dev/aptly#1483)
  * DEPENDENCIES CHANGES:
  * Go toolchain → 1.25.0
  * `go.opentelemetry.io/otel` → v1.41.0 (aptly-dev/aptly#1586)
  * `go.opentelemetry.io/otel/sdk` → v1.43.0 (aptly-dev/aptly#1584)
  * `github.com/go-jose/go-jose/v4` → v4.1.4 (aptly-dev/aptly#1585)
  * `github.com/go-git/go-git/v5` → v5.19.1 (aptly-dev/aptly#1590)
  * `github.com/ulikunitz/xz` → v0.5.15 (fixes 32-bit build failures)
  * `golang.org/x/crypto` → v0.45.0 (aptly-dev/aptly#1506)
  * `google.golang.org/grpc` → v1.79.3 (aptly-dev/aptly#1546)
  * `github.com/aws/aws-sdk-go-v2/service/s3` → v1.97.3 (aptly-dev/aptly#1554)
  * `github.com/cloudflare/circl` → v1.6.3 (aptly-dev/aptly#1461), aptly-dev/aptly#1541)
  * `requests` (Python, system tests) → 2.33.0 (aptly-dev/aptly#1460), aptly-dev/aptly#1547)
  * `github.com/ProtonMail/go-crypto` → v1.4.0
  * `golang.org/x/net` → v0.48.0
</pre>
  <p>View the full release notes at <a href="https://github.com/aptly-dev/aptly/releases/tag/v1.6.3">https://github.com/aptly-dev/aptly/releases/tag/v1.6.3</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!12365
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FR?] InRelease Signed-By field support

2 participants