Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

File 'repomd.xml' from repository 'Copr repo for onedriver owned by jstaf' is unsigned. #395

Open
lgaudreau opened this issue May 5, 2024 · 0 comments

Comments

@lgaudreau
Copy link

After installing the Copr repository in OpenSUSE Tumbleweed with no errors or warnings and trying to install the package, this warning is returned:

Warning: File 'repomd.xml' from repository 'Copr repo for onedriver owned by jstaf' is unsigned.

There is an option to proceed with the installation with the warning that there is no guarantee the file was not modified or compromised.

Operating System: OpenSUSE Tumbleweed version 20240502

Steps to reproduce:

  1. install Copr repository:

sudo zypper addrepo -g -r https://copr.fedorainfracloud.org/coprs/jstaf/onedriver/repo/opensuse-tumbleweed/jstaf-onedriver-opensuse-tumbleweed.repo onedriver
sudo zypper --gpg-auto-import-keys refresh

  1. Install onedriver:

sudo zypper install onedriver
Warning: File 'repomd.xml' from repository 'Copr repo for onedriver owned by jstaf' is unsigned.

Note: Signing data enables the recipient to verify that no modifications
occurred after the data were signed. Accepting data with no, wrong or
unknown signature can lead to a corrupted system and in extreme cases even
to a system compromise.

Note: File 'repomd.xml' is the repositories master index file. It ensures
the integrity of the whole repo.

Warning: We can't verify that no one meddled with this file, so it might not
be trustworthy anymore! You should not continue unless you know it's safe.

File 'repomd.xml' from repository 'Copr repo for onedriver owned by jstaf' is unsigned.
Continue? [yes/no] (no):

Expected behaviour: repomd.xml file is signed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant