Skip to content

Pin the bundled CA certificates to a dated curl release - #541

Merged
LouisParkin merged 1 commit into
stackstate-7.78.2from
pin-cacerts
Oct 1, 2026
Merged

LouisParkin merged 1 commit into
stackstate-7.78.2from
pin-cacerts

Conversation

@LouisParkin

Copy link
Copy Markdown

DEB package builds are failing on every branch: the cacerts recipe downloads the moving https://curl.se/ca/cacert.pem against a pinned SHA-256, and curl published a new bundle on 2026-09-25. This pins the dated release cacert-2026-09-25.pem instead. Its checksum matches curl's published .sha256, and it's the same content as today's cacert.pem. New curl releases no longer break builds; updating the bundle becomes a deliberate change of version and checksum.

Fixes #540

Validation: the recipe parses (ruby -c). The DEB package build on this branch is the real check.

🤖 Generated with Claude Code

The moving cacert.pem fails checksum verification whenever curl publishes a new bundle.
@LouisParkin
LouisParkin added this pull request to the merge queue Oct 1, 2026
Merged via the queue into stackstate-7.78.2 with commit ea7629e Oct 1, 2026
42 checks passed
@LouisParkin
LouisParkin deleted the pin-cacerts branch October 1, 2026 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pin the bundled CA certificates to a dated curl release

2 participants