GitLab Installation and Updates
The GPG key used to sign GitLab Runner packages has been rotated

The GPG key used to sign GitLab Runner packages has been rotated

6/16/2021 · Elliot Rushton

What this post added

This post details the rotation of the GPG key used to sign official GitLab Runner packages due to a security incident where the key and other distribution tokens were not secured according to policy. It provides the old and new GPG key fingerprints, explains the impact on users (none for shared runners, action required for those using package signature verification), and outlines the steps for updating the key. It also clarifies that new users are unaffected but should use the new key for verification.

Read the original post ↗