Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 20 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,9 +57,28 @@ echo "deb [signed-by=/etc/apt/keyrings/guysinc-apt.gpg] https://apt.guysinc.pub/
sudo apt update && sudo apt install github-desktop
```

The repository is GPG-signed; the signing key fingerprint is
The repository is GPG-signed; the fingerprint to verify is
`F45B B6D3 4D82 EF56 BB97 FBE0 F305 FB33 592B 46C8`.

That is the *primary* key. `gpg --show-keys` will also list signing subkeys — one per
project — and it is a subkey that signs this repository. The primary certifies the
subkeys, stays offline, and survives their rotation, which is why it is the one
published here.

### How the repository is published

The signing and publishing half of this pipeline is being extracted into
**[archivist](https://github.com/Guys-Inc-Public/archivist)**, a separate MIT-licensed
project: point it at a directory of `.deb` files and get a signed apt repository on
storage you own. If you have been putting loose `.deb` files on a Releases page because
`reprepro`, GPG-in-CI and repository metadata looked like too much work, that is the
problem it exists to remove.

It is **pre-release** — the design and the decision records are written down, the CLI is
not finished, and this repository still publishes with `reprepro` directly today. Nothing
to install yet; the [roadmap](https://github.com/Guys-Inc-Public/archivist/blob/main/docs/Roadmap.md)
is the honest status.

## Other distributions

Prebuilt packages for every release are on the
Expand Down
15 changes: 14 additions & 1 deletion apt/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -76,8 +76,21 @@ <h2>Why this build?</h2>
<section>
<h2>Verify the signing key</h2>
<div class="card">
<p style="margin:0 0 6px">Fingerprint of the repository signing key:</p>
<p style="margin:0 0 6px">Fingerprint of the primary key — this is the one to check:</p>
<p class="fp">F45B B6D3 4D82 EF56 BB97 FBE0 F305 FB33 592B 46C8</p>
<p style="margin:10px 0 0;color:var(--muted);font-size:.92rem"><code>gpg --show-keys</code> will also list signing subkeys, one per project, and it is a
subkey that actually signs this repository. The primary certifies them, stays offline, and does not change when a
subkey is rotated — so it is the fingerprint worth writing down.</p>
</div>
</section>

<section>
<h2>How this repository is built</h2>
<div class="card">
<p style="margin:0 0 6px">Nothing here is hand-rolled per release. The signing and publishing steps are being extracted into
<a href="https://github.com/Guys-Inc-Public/archivist">archivist</a> — an MIT-licensed tool that turns a directory of
<code>.deb</code> files into a signed apt repository on storage you own. It is still pre-release; if you want the same setup
for your own project, follow along there.</p>
</div>
</section>
</div>
Expand Down
Loading