Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

The GPG key used to sign GitLab Runner packages has been rotated

Blog post from GitLab

Post Details
Company
Date Published
Author
Elliot Rushton
Word Count
420
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab recently discovered a security lapse involving the GPG key and other tokens used for signing and distributing GitLab Runner packages, which were not secured in accordance with their security policies. Although no unauthorized modifications or access to packages were found, GitLab has proactively rotated the GPG key and all related tokens to ensure security. The old key, identified by the fingerprint 3018 3AC2 C4E2 3A40 9EFB E705 9CE4 5ABC 8807 21D4, has been revoked, and a new key, with the fingerprint 09E5 7083 F34C CA94 D541 BC58 A674 BF81 35DF A027, is now in use for signing packages starting June 13, 2021. Users who utilize package signature verification for DEB or RPM packages must update their key to ensure continued security, while those not using verification remain unaffected. GitLab advises treating the old key as compromised and recommends using the new key for trustworthiness. New users are not impacted by this change but should ensure they have the new key if they wish to use package signature verification. Further details and configuration information can be found on GitLab's documentation site, and additional queries can be directed to GitLab Support.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.