
2/20/2026 · Pratik Singh
What this post added
The Omnibus package signing key, previously set to expire on Feb. 14, 2026, has been extended to expire on Feb. 16, 2028. This extension is a periodic measure to comply with GitLab security policies and limit exposure in case of compromise. The extension, rather than a rotation, is chosen to minimize disruption for users who validate package signatures. Users who validate signatures need to update their copy of the package signing key.