Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

The GPG key used to sign GitLab package repositories' metadata is changing

Blog post from GitLab

Post Details
Company
Date Published
Author
Balasankar 'Balu' C
Word Count
400
Company Posts That Month
29
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab employs a Packagecloud instance to distribute official omnibus-gitlab and gitlab-runner packages, ensuring the integrity of these packages by signing the metadata of apt and yum repositories with a GPG key, separate from the key used to sign the packages themselves. The current GPG key for metadata signing is set to expire on April 15, 2020, prompting GitLab to replace it with a new key, effective from April 6, 2020, with a validity of two years. Existing users who have configured their systems to use these repositories must update their configurations by fetching the new public key to continue accessing packages, as the change will prevent them from downloading packages until the new key is installed. New users, however, will not be affected, as the installation scripts will automatically incorporate the new key. Users experiencing issues are advised to consult GitLab's official documentation or open an issue in the omnibus-gitlab issue tracker for assistance.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.