Skip to content

.github: workflows: qubesos.yml: add trigger-woodpecker-cicd job for signing#26

Closed
DaniilKl wants to merge 1 commit into
masterfrom
add-signing-job
Closed

.github: workflows: qubesos.yml: add trigger-woodpecker-cicd job for signing#26
DaniilKl wants to merge 1 commit into
masterfrom
add-signing-job

Conversation

@DaniilKl
Copy link
Copy Markdown

Related to this PR TrenchBoot/.github#16 .

Comment thread .github/workflows/qubesos.yml Outdated
Comment thread .github/workflows/qubesos.yml Outdated
Comment thread .github/workflows/qubesos.yml Outdated
@DaniilKl DaniilKl force-pushed the add-signing-job branch 2 times, most recently from 6340b7d to 787c0ee Compare April 27, 2026 18:10
@DaniilKl DaniilKl requested a review from m-iwanicki April 27, 2026 18:10
Comment thread .github/workflows/qubesos.yml
Comment thread .github/workflows/qubesos-rc.yml Outdated
signing

Signed-off-by: Danil Klimuk <daniil.klimuk@3mdeb.com>
Copy link
Copy Markdown

@m-iwanicki m-iwanicki left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@DaniilKl
Copy link
Copy Markdown
Author

@DaniilKl As you can see, woodpecker failed (missing token?): https://github.com/TrenchBoot/secure-kernel-loader/actions/runs/25159637133/job/73751113565

Yes, missing token. I am discussing this with organization admins.

@DaniilKl
Copy link
Copy Markdown
Author

DaniilKl commented Apr 30, 2026

I am closing this, as there were a decision to not use the access via tokens stored as GitHub secrets to the ci.3mdeb.com for security reasons. This is to prevent the tokens leak from GitHub, that could compromise the packages that will be signed and/or the entire ci.3mdeb.com instance. Reason: the Woodpecker does not have scoped access control for its tokens, every token give the full access to a Woodpecker instance.

@DaniilKl DaniilKl closed this Apr 30, 2026
@DaniilKl DaniilKl deleted the add-signing-job branch April 30, 2026 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants