Sitelet https://github.com/nodejs/docker-node/issues/2592
Skip to content

Only include the releaser key for the person that signed the individual release #2592

Description

@nschonni

Problem

Currently, all the Node.js releaser keys are read/validated during the image build, so things like #2591 can crop up. Releasers that may not be involved in the active releases are also included in the list of fingerprints.

Solution

In the update.sh (or replacement), read from the individual release's SHASUM.txt and find the single fingerprint that was used to sign the release, and just include that one fingerprint in the Dockerfile. That fingerprint should still be validated that it is in the node.keys prior to inclusion.

Alternatives to Consider

Using/changing to a single key might cause more "git noise" than the current diffs, but is similar to the CHECKSUM noise we have with the Alpine images.

Activity

  1. MikeMcC399 commented on Aug 5, 2026

    @MikeMcC399
    Contributor

    That would make the Dockerfile cleaner. I imagine the "noise" would be tolerable though.

    This issue is a duplicate of #1511 however!

  2. added
    keysRelated to keys used to sign releases
    on Aug 5, 2026
  3. nschonni commented on Aug 5, 2026

    @nschonni
    MemberAuthor

    Thanks, I skimmed the open issues before creating this, but must menally ignore myself

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    keysRelated to keys used to sign releases

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions