[pve-devel] applied: [PATCH proxmox-secure-boot-support] ship apt pinning snippet

Thomas Lamprecht t.lamprecht at proxmox.com
Fri Jun 21 11:22:58 CEST 2024


On 21/06/2024 09:04, Fabian Grünbichler wrote:
> this should ensure that a shim-signed package from a non-Proxmox repository
> cannot overtake ours, even if the version is newer. since
> proxmox-secure-boot-support is optional, this is entirely opt-in.
> 
> Signed-off-by: Fabian Grünbichler <f.gruenbichler at proxmox.com>
> ---
> not the most elegant solution, but the only one I could come up with. the next
> bookworm point release will likely ship with a shim-signed version higher than
> our current one, so we probably want to roll this out rather fast..
> 
>  debian/99-proxmox-secure-boot-support      | 7 +++++++
>  debian/proxmox-secure-boot-support.install | 1 +
>  2 files changed, 8 insertions(+)
>  create mode 100644 debian/99-proxmox-secure-boot-support
>  create mode 100644 debian/proxmox-secure-boot-support.install
> 
>

applied, thanks!




More information about the pve-devel mailing list