<feed xmlns='http://www.w3.org/2005/Atom'>
<title>efi-boot-shim.git, branch buster/updates</title>
<subtitle> (mirror of https://github.com/vyos/efi-boot-shim.git)
</subtitle>
<id>https://git.amelek.net/vyos/efi-boot-shim.git/atom?h=buster%2Fupdates</id>
<link rel='self' href='https://git.amelek.net/vyos/efi-boot-shim.git/atom?h=buster%2Fupdates'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/'/>
<updated>2024-05-12T21:04:29+00:00</updated>
<entry>
<title>Switch distribution to buster-security</title>
<updated>2024-05-12T21:04:29+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-05-12T21:04:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=485d07436d26c1f81fbb54d52a1f0f2e193ebdf5'/>
<id>urn:sha1:485d07436d26c1f81fbb54d52a1f0f2e193ebdf5</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add salsa-ci</title>
<updated>2024-05-06T19:22:47+00:00</updated>
<author>
<name>Bastien Roucariès</name>
<email>rouca@debian.org</email>
</author>
<published>2024-05-06T19:22:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=c8691620c518559492431d45b2ab29d4cdb7001b'/>
<id>urn:sha1:c8691620c518559492431d45b2ab29d4cdb7001b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Release 15.8-1~deb10u1 for buster</title>
<updated>2024-05-06T19:21:02+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-05-06T10:34:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=e2081dcd554b34e2041efda7007542984429e7da'/>
<id>urn:sha1:e2081dcd554b34e2041efda7007542984429e7da</id>
<content type='text'>
</content>
</entry>
<entry>
<title>check_nx: ignore arm64 binaries</title>
<updated>2024-05-06T19:20:08+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-05-05T00:39:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=bbe9ce920070e2860200559870afa5df42ee828a'/>
<id>urn:sha1:bbe9ce920070e2860200559870afa5df42ee828a</id>
<content type='text'>
the toolchain is too old
</content>
</entry>
<entry>
<title>Tweak arm64 patch</title>
<updated>2024-05-06T19:20:02+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-05-05T00:21:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=dfd38f5f958ae71078be4ab9035be954b9220451'/>
<id>urn:sha1:dfd38f5f958ae71078be4ab9035be954b9220451</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Clean up better after build. Closes: #1046268</title>
<updated>2024-05-06T19:19:55+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-05-04T13:54:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=4da234ce0b772716d9e4fd08d454b27464faab9d'/>
<id>urn:sha1:4da234ce0b772716d9e4fd08d454b27464faab9d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Install a copy of the Debian CA certificate into /usr/share/shim.</title>
<updated>2024-05-06T19:19:49+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-05-04T13:36:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=c9630addcac391372108d5569844110e21173b36'/>
<id>urn:sha1:c9630addcac391372108d5569844110e21173b36</id>
<content type='text'>
Closes: #1069054
</content>
</entry>
<entry>
<title>Force usage of newest revocations at build time</title>
<updated>2024-05-06T19:19:41+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-05-03T13:46:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=2c35bd94ca9a772abc228060ed0ce0a7cb4af461'/>
<id>urn:sha1:2c35bd94ca9a772abc228060ed0ce0a7cb4af461</id>
<content type='text'>
Force shim to use the latest revocations by default to block some
older grub / peimage issues. This is:

"shim,4\ngrub,4\ngrub.peimage,2\n"

This should work with the current released grub builds in all of
buster, bullseye, bookwork and trixie/unstable. Let's not leave known
security holes in the wild.
</content>
</entry>
<entry>
<title>Cherry-pick latest grub revocation patches from upstream shim</title>
<updated>2024-05-06T19:19:24+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-04-25T23:58:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=0c07782d919b58d514faecaea1534eadeac3ee0b'/>
<id>urn:sha1:0c07782d919b58d514faecaea1534eadeac3ee0b</id>
<content type='text'>
0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch
0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch
</content>
</entry>
<entry>
<title>Log if the build is nx-compatible or not</title>
<updated>2024-05-06T19:19:16+00:00</updated>
<author>
<name>Steve McIntyre</name>
<email>steve@einval.com</email>
</author>
<published>2024-04-25T21:42:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/efi-boot-shim.git/commit/?id=2a669792da370a7d43becc33e97d36e1405a9c4a'/>
<id>urn:sha1:2a669792da370a7d43becc33e97d36e1405a9c4a</id>
<content type='text'>
Add a new simple script to do this: check_nx
</content>
</entry>
</feed>
