Skip to content

Conversation

@iloveitaly
Copy link
Collaborator

@iloveitaly iloveitaly commented Nov 18, 2025

  • Adds MISE_GPG_VERIFY=1 environment variable to enable GPG signature verification when installing tools via mise in container builds. This has a None default.
  • It's unclear what the blast impact of this is. All of the test fail, but this could cause additional failures in production (due to the latest node verification issue we ran into in the past). However, I think this is worth the risk. We should opt for additional security measures when we can.

@iloveitaly iloveitaly requested a review from coffee-cup January 15, 2026 22:58
@iloveitaly iloveitaly force-pushed the claude/enable-mise-gpg-verify-01Xayb4MHHnUcmtJThEqB4Nw branch from c36bcea to b3ca578 Compare January 15, 2026 23:00
@iloveitaly iloveitaly marked this pull request as ready for review January 15, 2026 23:00
@iloveitaly iloveitaly force-pushed the claude/enable-mise-gpg-verify-01Xayb4MHHnUcmtJThEqB4Nw branch from 1a55523 to 9f8e8c0 Compare January 15, 2026 23:03
Copy link
Contributor

@coffee-cup coffee-cup left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thoughts on having this disabled by default initially and opt-in? I'm just worried that we start breaking a bunch of builds in production and then just disable it (and then what is the point?)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants