From aafc4efe1f235c9eca86c5ea6138228ae4f620c2 Mon Sep 17 00:00:00 2001 From: neil Date: Sun, 20 Sep 2026 13:13:20 +0200 Subject: [PATCH] allowed_signers: point the examples at 3.1.6 The comment block told the reader to run "git verify-tag 3.1.5", which is exactly the tag that fails: 3.1.5 was tagged by the GitHub release form as a lightweight ref and carries no signature. Use 3.1.6 in the examples and state the baseline, so the file that teaches verification does not hand out a command that cannot work. https://github.com/acmesh-official/acme.sh/issues/7273 --- allowed_signers | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/allowed_signers b/allowed_signers index 8ed9d0a7..d8448183 100644 --- a/allowed_signers +++ b/allowed_signers @@ -4,17 +4,19 @@ # maintainer and is never available to CI, so a compromise of the build # pipeline cannot produce a tag that verifies against this file. # +# Signing starts at 3.1.6; tags up to 3.1.5 are unsigned. +# # Fingerprint: SHA256:M60qVafm/NUywQHXAkoQcj2v6KgkfrdSXv6mPejUUeE # # To verify a release tag, from a clone of this repository: # # git config gpg.ssh.allowedSignersFile allowed_signers -# git verify-tag 3.1.5 +# git verify-tag 3.1.6 # # A good signature covers the tag object, which pins the commit, which pins # the whole tree -- so verifying the tag verifies every file at that # release. Build a tarball from the verified tag with: # -# git archive --format=tar.gz --prefix=acme.sh-3.1.5/ 3.1.5 > acme.sh-3.1.5.tar.gz +# git archive --format=tar.gz --prefix=acme.sh-3.1.6/ 3.1.6 > acme.sh-3.1.6.tar.gz # github@neilpang.com namespaces="git" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBTjI0HBJn3uhfT2DsNcFybfAZi3ADbIacMpz1BItKdB