1637564abc
- Update to version 0.18: * logging: fixup new go vet warning * workflows: add cc for cross compile * workflow: add sudo to apt * workflow: add pcsclite to ci * workflow: try enable cgo * go.mod: update golang.org/x/ dependencies * fix: avoid adding bogus Country attribute to subject DNs * sbctl: only store file if we did actually sign the file * installkernel: add post install hook for Debian's traditional installkernel * CI: missing libpcsclite pkg * workflows: add missing depends and new pattern keyword * Add yubikey example for create keys to the README * Initial yubikey backend keytype support * verify: ensure we pass args in correct order
Jan Loeser
2025-10-13 09:29:00 +00:00
c60bbc1c3c
Accepting request 1302168 from utilities
Ana Guerrero2025-09-01 15:18:43 +00:00
5c51d31a33
- bsc#1248949 (CVE-2025-58058): Bump xz to 0.5.14
Michael Vetter2025-09-01 09:40:51 +00:00
dae1d4d9fa
Accepting request 1274530 from utilities
Ana Guerrero2025-05-05 20:29:15 +00:00
07ab3bca73
- Update to version 0.17: * Ensure we don't wrongly compare input/output files when signing * Added --json supprt to sbctl verify * Ensure sbctl setup with no arguments returns a helpful output * Import latest Microsoft keys for KEK and db databases * Ensure we print the path of the file when encountering an invalid PE file * Misc fixups in tests * Misc typo fixes in prints
Jan Loeser
2025-05-05 11:38:27 +00:00
46227b9917
- Disable tests that fail due to gh/foxboron/sbctl#343 - Update to version 0.16: * Ensure sbctl reads --config even if /etc/sbctl/sbctl.conf is present * Fixed a bug where sbctl would abort if the TPM eventlog contains the same byte multiple times * Fixed a landlock bug where enroll-keys --export did not work * Fixed a bug where an ESP mounted to multiple paths would not be detected * Exporting keys without efivars present work again * sbctl sign will now use the saved output path if the signed file is enrolled * enroll-keys --append will now work without --force. - Updates from version 0.15.4: * Fixed an issue where sign-all did not report a non-zero exit code when something failed * Fixed and issue where we couldn't write to a file with landlock * Fixed an issue where --json would print the human readable output and the json * Fixes landlock for UKI/bundles by disabling the sandbox feature * Some doc fixups that mentioned /usr/share/
Jan Loeser
2024-11-11 07:48:00 +00:00