Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Run the GPG sign job after the SBOM sign #1175

Merged
merged 2 commits into from
Jan 6, 2025

Conversation

Haroon-Khel
Copy link
Contributor

@Haroon-Khel Haroon-Khel commented Jan 6, 2025

If the SBOM jsf sign happens after the SBOM has been signed by the gpg key, the signature will be invalid. Nice catch Stewart

Copy link

github-actions bot commented Jan 6, 2025

Thank you for creating a pull request!

Please check out the information below if you have not made a pull request here before (or if you need a reminder how things work).

Code Quality and Contributing Guidelines

If you have not done so already, please familiarise yourself with our Contributing Guidelines and Code Of Conduct, even if you have contributed before.

Tests

Github actions will run a set of jobs against your PR that will lint and unit test your changes. Keep an eye out for the results from these on the latest commit you submitted. For more information, please see our testing documentation.

In order to run the advanced pipeline tests (executing a set of mock pipelines), it requires an admin to post run tests on this PR.
If you are not an admin, please ask for one's attention in #infrastructure on Slack or ping one here.
To run full set of tests, use "run tests"; a subset of tests on specific jdk version, use "run tests quick 11,21"

@Haroon-Khel
Copy link
Contributor Author

Copy link
Member

@sxa sxa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM but to avoid ambiguity can we also update the name of the stage at line 1066:
context.stage('SBOM JSF Sign') {

@Haroon-Khel
Copy link
Contributor Author

Im able to verify the SBOM from the above build

hkhel@hkhel-mac ~ % gpg --verify OpenJDK17U-sbom_x64_linux_hotspot_2025-01-06-14-26.json.sig OpenJDK17U-sbom_x64_linux_hotspot_2025-01-06-14-26.json
gpg: Signature made Mon  6 Jan 15:18:47 2025 GMT
gpg:                using RSA key 3B04D753C9050D9A5D343F39843C48A565F8F04B
gpg: Good signature from "Adoptium GPG Key (DEB/RPM Signing Key) <[email protected]>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: 3B04 D753 C905 0D9A 5D34  3F39 843C 48A5 65F8 F04B

@Haroon-Khel Haroon-Khel merged commit 7ea3ed1 into adoptium:master Jan 6, 2025
8 checks passed
@Haroon-Khel Haroon-Khel deleted the gpg.after.jsf branch January 6, 2025 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants