
6/16/2021 · Elliot Rushton
What this post added
This post details the rotation of the GPG key used to sign official GitLab Runner packages due to a security incident where the key and other distribution tokens were not secured according to policy. It provides the old and new GPG key fingerprints, explains the impact on users (none for shared runners, action required for those using package signature verification), and outlines the steps for updating the key. It also clarifies that new users are unaffected but should use the new key for verification.