Pin external APT signing keys by primary-key fingerprint - #172
Merged
Merged
Conversation
The image build trusted the GitHub CLI and Eza APT signing keys on download alone, and fetched the Eza key from the mutable eza `main` branch. A changed or compromised key URL would silently become a trusted build signer. - Add GH_CLI_KEY_FINGERPRINTS / EZA_KEY_FINGERPRINTS ARGs holding the full 40-hex primary-key fingerprints, and require each downloaded keyring to contain exactly that primary-key set (subkeys ignored) before it is installed under /etc/apt/keyrings or referenced by a source list. - Download keys to files instead of piping curl, so a failed fetch fails. - Pin the Eza key URL to commit 1cff499f (the only commit touching deb.asc). - Add tests/test-apt-key-policy.sh static policy test. - Document the control and the out-of-band rotation procedure in SECURITY.md. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dockerfile step "2a. External APT repos" downloaded the GitHub CLI and Eza APT signing keys with no fingerprint check (Eza's from the mutable
mainbranch), so a changed or compromised key URL would silently become a trusted signer for the build.GH_CLI_KEY_FINGERPRINTSandEZA_KEY_FINGERPRINTS(space-separated, upper-case, 40-hex).verify_apt_keyextracts primary-key fingerprints only (pub→ followingfpr; subkeys ignored) viagpg --show-keys --with-colonsin a throwawayGNUPGHOME, and requires the downloaded keyring to contain exactly the expected set. Mismatches fail the build with expected/actual output, before any keyring is installed into/etc/apt/keyringsor any source list is written.curl -o) rather thancurl | tee, so a failed fetch can no longer pass silently.eza-community/eza@1cff499fb218f2a133aafa01824ddab090f4389e, the only commit that touchesdeb.asc. The file at that commit is byte-identical tomain.gh/ezainstall.tests/test-apt-key-policy.sh(picked up by thefind tests ... test-*.shloop in build.yml) checks that every downloaded key is verified before use, that the ARG values are 40-hex, and that the Eza URL is SHA-pinned. I mutation-checked it against six Dockerfile mutations and against origin/main, and it failed in every case.Pinned fingerprints
2C6106201985B60E6C7AC87323F3D4EA75716059(expired 2026-09, still shipped in the keyring),7F38BBB59D064DBCB3D84D725612B36462313325(current)cli/clidocs/install_linux.md. The downloaded keyring's SHA-256 (6084d5d7…811b) matches the doc. The livecli.github.com/packages/dists/stable/Release.gpgissuer is7F38BB…1325.1548BC8A4B4D2688F9B0DAF7EC29E2090CE3FD43deb.gierens.de/dists/stable/Release.gpgissuer fpr matches.deb.aschas a single commit in history (2023-08-20). keys.openpgp.org and keyserver.ubuntu.com don't host this key, and eza's INSTALL.md publishes no fingerprint.Test plan
podman build --build-arg SQUAREBOX_VERSION=dev -t squarebox:keytest .succeeds and logsVerified …for both keys.gh2.102.0 andeza0.23.5 are installed, and/etc/apt/keyringsplus the extra source lists are empty afterwards.scripts/e2e-test.sh smokeagainst that image: 62/62 pass.--build-arg GH_CLI_KEY_FINGERPRINTS=000…0fails at step 2a withGitHub CLI APT signing key fingerprint mismatch.Eza APT signing key fingerprint mismatch, which shows the comparison is an exact set and not a subset.tests/test-*.shpass. shellcheck (koalaman/shellcheck:stable, severity=warning) is clean on the new test.Note: GitHub's keyring still includes the expired
2C61…key. When GitHub drops it, this build will fail by design until the ARG is updated after review.🤖 Generated with Claude Code