Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Drop rpms-signature-scan from fbc required tasks #64

Merged
merged 1 commit into from
Oct 18, 2024
Merged

Conversation

ralphbean
Copy link
Member

FBC images are "catalog fragments" that are never actually shipped. They only exist to convey data to the process that updates the global index image. It is unreasonable to scan them for rpm content.

Even if they somehow included unsigned rpm content, that content is never going to be exposed.

FBC images are "catalog fragments" that are never actually shipped.
They only exist to convey data to the process that updates the global
index image. It is unreasonable to scan them for rpm content.

Even if they somehow included unsigned rpm content, that content is
never going to be exposed.
@lcarva lcarva merged commit 2db4ffa into main Oct 18, 2024
1 check passed
@lcarva lcarva deleted the fbc-has-no-rpms branch October 18, 2024 00:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants