Skip to content

fix: parse every embedded Node release key - #28

Merged
MoorZhou merged 1 commit into
mainfrom
feature/v1.0.0-release-tests
Aug 17, 2026
Merged

fix: parse every embedded Node release key#28
MoorZhou merged 1 commit into
mainfrom
feature/v1.0.0-release-tests

Conversation

@MoorZhou

Copy link
Copy Markdown
Contributor

Summary

  • parse each independently armored Node.js release certificate instead of treating the concatenated bundle as one armor payload
  • keep self-signature, fingerprint allowlist, duplicate, and complete-set checks fail-closed
  • add offline coverage for the complete embedded trust store and malformed armor boundaries

Validation

  • static diff review, Rustfmt, and git diff --check completed locally
  • no local or WSL build, test, Pinset execution, or Provider download performed
  • GitHub Actions will perform the four-platform build validation

@MoorZhou
MoorZhou merged commit 0f4f16f into main Aug 17, 2026
4 checks passed
@MoorZhou
MoorZhou deleted the feature/v1.0.0-release-tests branch August 17, 2026 04:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant