-
Notifications
You must be signed in to change notification settings - Fork 8.1k
Use SHA256 as digest for RPM packages (FIPS compliance) #16896
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
This pull request has been automatically marked as Review Needed because it has been there has not been any activity for 7 days. |
|
Subscribing to this PR for updates. |
|
This PR has Quantification details
Why proper sizing of changes matters
Optimal pull request sizes drive a better predictable PR flow as they strike a
What can I do to optimize my changes
How to interpret the change counts in git diff output
Was this comment helpful? 👍 :ok_hand: :thumbsdown: (Email) |
|
@ngharo Thank you for fixing this. |
|
windows packaging failures are unrelated |
|
/backport to release/v7.2.4 |
|
Started backporting to release/v7.2.4: https://github.com/PowerShell/PowerShell/actions/runs/2242305687
|
This comment was marked as outdated.
This comment was marked as outdated.
|
/backport to release/v7.2.4 |
|
Started backporting to release/v7.2.4: https://github.com/PowerShell/PowerShell/actions/runs/2242314317
|
|
🎉 Handy links: |
Set the RPM digest algorithm to SHA256 when distribution target is Red Hat.
PR Context
fpm is used to build the rpm package. By default, the rpm digest will use md5. md5 is not FIPS compliant. If I specify sha256 as an option during the build I am able to install correctly.
Fixes #15866
PR Checklist
.h,.cpp,.cs,.ps1and.psm1files have the correct copyright headerWIP:or[ WIP ]to the beginning of the title (theWIPbot will keep its status check atPendingwhile the prefix is present) and remove the prefix when the PR is ready.