-
Notifications
You must be signed in to change notification settings - Fork 566
fix(node): Use dl.yarnpkg.com for Yarn GPG key on all Debian versions #1547
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(node): Use dl.yarnpkg.com for Yarn GPG key on all Debian versions #1547
Conversation
Branch-Creation-Time: 2026-01-29T00:16:22+0000
Kaniska244
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you for the fix. Would you kindly bump up the node feature version to 1.6.5?
|
Can you please speed this up a bit? I'm currently pretty much blocked since all of my devcontainers refuse to build due to this issue. @Kaniska244 I love updates. But please don't mix them with critical bugfixes in the same PR. |
Hi @max06 Request you to follow this issue for updates and workaround. |
yep! Done. Please let me know if anything else needs to be modified. Thanks! |
|
@microsoft-github-policy-service agree |
Hi @Kaniska244 I'm aware of that workaround. But since I'm using the image as an image in my devcontainers and not as base in a local dockerfile, I can't apply the workarounds there. That's why I need that updated image. |
|
Quick check on this. Are we able to get this merged or does it need some additional things? |
Problem
Yarn rotated their signing key on 2026-01-28. The previous fix (#1546) for Debian trixie
fetched the key from
keys.openpgp.orgusing a specific fingerprint, but that sourceonly has the old key.
Additionally, the old signing subkeys expired on 2026-01-23, breaking all existing
installations that haven't refreshed their keys.
Solution
dl.yarnpkg.com/debian/pubkey.gpgfor all Debian versions/etc/apt/keyrings/as the keyring location (modern standard)Verification