
2/24/2026 · Denis Afonso
What this post added
This post details the extension of the GPG key used to sign the metadata of GitLab's apt and yum repositories. The current key, with fingerprint F640 3F65 44A3 8863 DAA0 B6E0 3F01 618A 5131 2F3F, has been extended from February 27, 2026, to February 6, 2028. This extension is a security measure to limit exposure in case of compromise and to reduce disruption for users compared to a full key rotation. Instructions are provided for users who have already configured repositories to update their trusted key, while new users will automatically receive the correct key during installation.