qusal/scripts
Ben Grande fc22726ee8
feat: build and sign RPM packages
Passing files to Dom0 is always dangerous:

- Passing a git repository is dangerous as it can have ignored modified
  files and signature verification will pass.
- Passing an archive is troublesome for updates.
- Passing an RPM package depends on the RPM verification to be correct,
  some times it is not.
- Passing a RPM repository definition is less troublesome for the user,
  as it is a small file to verify the contents and update mechanism is
  via the package manager. Trust in RPM verification is still required.

Many improvements were made to the build scripts:

- requires-program: Single function to check if program is installed;
- spec-get: Sort project names for the usage message;
- spec-get: Only running commands that are necessary;
- spec-get: Fix empty summary when readme has copyright header;
- spec-gen: Fix grep warning of escaped symbol;
- spec-build: Sign RPM and verify signature;
- spec-build: Only lint the first SPEC for faster runtime;
- yumrepo-gen: Generate a local yum repository with signed metadata;
- qubesbuilder-gen: Generate a .qubesbuilder based on tracked projects;
- release: Build, sign and push all RPMs to repository.

Goal is to be able to build with qubes-builderv2 Qubes Executor.

For: https://github.com/ben-grande/qusal/issues/37
2024-06-12 14:44:04 +02:00
..
pgp-expiration.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00
qubesbuilder-gen.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00
release.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00
requires-program.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00
salt-fix.sh refactor: initial commit 2023-11-13 14:33:28 +00:00
salt-lint.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00
setup.sh chore: copyright update 2024-01-29 16:49:54 +01:00
shell-lint.sh refactor: initial commit 2023-11-13 14:33:28 +00:00
spec-build.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00
spec-gen.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00
spec-get.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00
toc-gen.sh refactor: initial commit 2023-11-13 14:33:28 +00:00
unicode-prohibit.sh feat: print hex of unicode 2024-03-14 12:09:49 +01:00
yumrepo-gen.sh feat: build and sign RPM packages 2024-06-12 14:44:04 +02:00