Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

GitLab rotating Omnibus Linux package signing key

Blog post from GitLab

Post Details
Company
Date Published
Author
GitLab
Word Count
246
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

On April 16, 2025, GitLab will rotate the GNU Privacy Guard (GPG) key used for signing all Omnibus Linux packages, crucial for ensuring package integrity and confirming they have not been altered post-creation in CI pipelines. The new key, with fingerprint 98BF DB87 FCF1 0076 416C 1E0B AD99 7ACC 82DD 593D, will replace the existing one, which will be revoked. Users who validate GPG signatures must update their key copy, although no action is needed for those who do not verify package signatures or have not configured their package manager for verification. The new key can be downloaded from packages.gitlab.com, and further documentation is available for those requiring assistance. If issues persist, users are encouraged to report them on the omnibus-gitlab issue tracker.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.