Skip to content

fix: validate Node signing authority precisely - #29

Merged
MoorZhou merged 1 commit into
mainfrom
feature/v1.0.0-release-certificates
Aug 17, 2026
Merged

fix: validate Node signing authority precisely#29
MoorZhou merged 1 commit into
mainfrom
feature/v1.0.0-release-certificates

Conversation

@MoorZhou

Copy link
Copy Markdown
Contributor

Summary

  • keep pinned primary fingerprints as the Node.js trust roots
  • validate every signing subkey binding and required back-signature
  • avoid treating unrelated historical third-party User ID certifications as self-signatures
  • preserve the explicit revoked-fingerprint denylist and complete allowlist checks

Validation

  • static diff review, Rustfmt, and git diff --check completed locally
  • no local or WSL build, test, Pinset execution, or Provider download performed
  • GitHub Actions will perform the four-platform build validation

@MoorZhou
MoorZhou merged commit 0951e77 into main Aug 17, 2026
4 checks passed
@MoorZhou
MoorZhou deleted the feature/v1.0.0-release-certificates branch August 17, 2026 04:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant