Skip to content

Add TrenchBoot packages for QubesOS docs#60

Merged
DaniilKl merged 3 commits into
masterfrom
qubesos-rc-cicds
May 15, 2026
Merged

Add TrenchBoot packages for QubesOS docs#60
DaniilKl merged 3 commits into
masterfrom
qubesos-rc-cicds

Conversation

@DaniilKl
Copy link
Copy Markdown
Contributor

No description provided.

@DaniilKl DaniilKl requested a review from m-iwanicki May 13, 2026 13:05
@DaniilKl DaniilKl force-pushed the qubesos-rc-cicds branch from 676326e to ce335ad Compare May 13, 2026 13:07
Comment thread docs/dev-docs/qubesos-packages-infra.md Outdated
Comment thread docs/dev-docs/qubesos-packages-infra.md Outdated
DaniilKl added 2 commits May 15, 2026 11:29
Signed-off-by: Danil Klimuk <daniil.klimuk@3mdeb.com>
…HTTP

This is to prevent Woodpecker token leaks that could compromise either
the process of signing the packages built as a part of TrenchBoot
project and/or entire ci.3mdeb.com instance. The reason: a Woodpecker
token cannot be configured only for workflow dispatch, instead it gives
access to an entire Woodpecker API including, among others, replacing the
signing key for the packages. By storing the token as a GitHub secret -
the entire TrenchBoot workflow relies on security of the GitHub and
proper management of the secrets (which is very error prone due to human
factor when designing the workflows). It was decided, that such a risk
is unacceptable either by 3mdeb and TrenchBoot project.

Signed-off-by: Danil Klimuk <daniil.klimuk@3mdeb.com>
@DaniilKl DaniilKl force-pushed the qubesos-rc-cicds branch from ce335ad to 6cc2f6a Compare May 15, 2026 09:30
@DaniilKl DaniilKl requested a review from m-iwanicki May 15, 2026 09:31
repositories and QubesOS components

Signed-off-by: Danil Klimuk <daniil.klimuk@3mdeb.com>
@DaniilKl DaniilKl merged commit 0be2e65 into master May 15, 2026
1 check passed
@DaniilKl DaniilKl deleted the qubesos-rc-cicds branch May 15, 2026 10:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants