summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2025-07-07Initial submission for VyOS (current)HEADvyos-shim-16.0-amd64-20250707mainChristian Breunig
2025-06-24Update example file to Ubuntu 24.04 ("noble")Christoph Biedl
Also adjust for the changes in the format of the package source definition.
2025-05-27Fix incorrect fingerprint for the detached signature on 16.0Steve McIntyre
Enhance the text here and include a copy of Peter's key too
2025-03-25Update shim-review issue template with data about 16.0Steve McIntyre
Signed-off-by: Steve McIntyre <steve@einval.com>
2025-03-05Add a question and simple docs about use of a CA certificateSteve McIntyre
We're seeing quite a few vendors using non-CA "CA" keys, and this is likely to cause problems in future.
2024-11-21Add text to describe the requirement for lockdown in LinuxSteve McIntyre
Signed-off-by: Steve McIntyre <steve@einval.com>
2024-11-11s/15.7/15.8/ in the reviewer guidelinesSteve McIntyre
2024-11-02Update Code of Conduct contact addressKamil Aronowski
Signed-off-by: Kamil Aronowski <kamil.aronowski@yahoo.com>
2024-10-08Ask for organization legal dataKamil Aronowski
The reviewers should be able to easily verify, that an organization is a legal entity, to prevent abuse. Ask for the information, which can prove the genuineness with certainty. Signed-off-by: Kamil Aronowski <kamil.aronowski@yahoo.com>
2024-05-29Ask what contributions have been made to help us with reviewingKamil Aronowski
As discussed during the May 27, 2024 meeting, the applicants shall be informed about this venue being a community peer-review work and how to help us speed up the process, rather than frequently chasing us for reviews. Signed-off-by: Kamil Aronowski <kamil.aronowski@yahoo.com>
2024-04-15Add clarifications suggested in review 1986775225Kamil Aronowski
Signed-off-by: Kamil Aronowski <kamil.aronowski@yahoo.com>
2024-04-08Request a link to an application with verified contactsKamil Aronowski
If security contacts have already been verified in an earlier application and haven't changed since the current one, let's point to that earlier application as part of the current one. Signed-off-by: Kamil Aronowski <kamil.aronowski@yahoo.com>
2024-03-19Add a note to explain that certificates must be in DER formatSteve McIntyre
2024-03-12Add UKI-specific line to expect .sbat section of UKIsLuca Boccassi
Allows to revoke a family of UKIs from a vendor, independently of the systemd-stub generation numbers.
2024-03-01Fixing spelling error #391Sherif Nagy
2024-02-22Clarify README question asking for all SBAT entries.Dan Streetman
Currently, the wording isn't clear (to me, at least) if it's asking for the shim SBAT or not; this clarifies that.
2024-02-13Guidelines: add examples for UKI .sbat sectionLuca Boccassi
The .sbat identifier of systemd-boot was split from the identifier of systemd-stub (which is used by UKI/kernel.efi binaries) after the previous release, so clarify this with concrete examples. Signed-off-by: Luca Boccassi <bluca@debian.org>
2024-02-05Ask about the NX bit and point to NX signing exceptionJulian Andres Klode
2024-02-02docs/submitting.md formatting fixes and updatesKamil Aronowski
Since the files in the docs/ directory were migrated from shim-review Wiki, some formatting errors remained. These have been fixed for the Markdown version, as well the text got some updates to reflect the current state of this initiative. Signed-off-by: Kamil Aronowski <kamil.aronowski@yahoo.com>
2024-02-02Adding examples for What changes since last SHIM submission questionSherif Nagy
2024-02-02Add questions and instructions regarding systemd-bootLuca Boccassi
Signed-off-by: Luca Boccassi <bluca@debian.org>
2024-01-30Update template to new shim versionMate Kukri
2023-11-06Add new GRUB2 CVEs, SBAT level and clarificationsThore Sommer
This also adds more details about the CVEs and unifies the spelling of GRUB2.
2023-09-25Minor spelling fixesKamil Aronowski
2023-09-25Merge docs from the wikiSteve McIntyre
2023-07-12Add question about how kernel modules are signedJulian Andres Klode
Signed-off-by: Julian Andres Klode <julian.klode@canonical.com>
2022-11-29Use unambiguous character for horizontal linesNicholas Bishop
In commonmark, `---` and `===` can be used to mark either [setext headings] or [thematic breaks] (aka horizontal lines). Headings take precendence, so if you aren't careful with line breaks you can make a heading where you meant to have a horizontal line. See [example] for a case of this happening. Fortunately, `***` is unambiguous: it will always create a horizontal line instead of a heading. Switch all the separators to that format so that we never have to worry about accidental headings again. [setext headings]: https://spec.commonmark.org/0.30/#setext-headings [thematic breaks]: https://spec.commonmark.org/0.30/#thematic-breaks [example]: https://github.com/rhboot/shim-review/blob/b8ebe98d7198174e95d9e62e4522c145ee9caa5b/README.md#this-should-include-logs-for-creating-the-buildroots-applying-patches-doing-the-build-creating-the-archives-etc
2022-11-18README: make formatting more consistentNicholas Bishop
On a few questions the `---` separators were missing or placed differently.
2022-11-17Update to shim 15.7Julian Andres Klode
Signed-off-by: Julian Andres Klode <julian.klode@canonical.com>
2022-11-17Update requirements for GRUB2 November 15th 2022 security updateJan Setje-Eilers
[julian: fix typo] Signed-off-by: Julian Andres Klode <julian.klode@canonical.com>
2022-11-01Add question about existing shim reuseRobbie Harwood
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-08-24Add an extra question about local kernel patchesSteve McIntyre
If people have arbitrary extra kernel patches, they could well break SB. Let's check?
2022-08-15Add link to previous review in issue templateRobbie Harwood
Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2022-07-07Add documentation for contact verificationSimon Becker
2022-06-07Fix some minor nitsPeter Jones
Signed-off-by: Peter Jones <pjones@redhat.com>
2022-06-07Update to 15.6Jan Setje-Eilers
Also update list of GRUB2 CVEs and add one more lockdown bypass fix.
2022-04-21Update to shim 15.5Nicholas Bishop
2022-03-23Clarify ISSUE_TEMPLATE, ensure SHA is recordedTed Brandston
* Change "Make sure you have provided the following information" to "Confirm the following are included in your repo, checking each box". "Make sure" makes it seem like the checklist is provided for your convenience, if you want to use it. [I don't think that's the case](https://github.com/rhboot/shim-review/issues/203#issuecomment-917067024). * Move the "link to your branch" to a full question - Remove the "in the form user/repo@tag". It seems okay [when people don't use that format](https://github.com/rhboot/shim-review/issues/233#issue-1165661688). That also doesn't work for non-github repos. - Add an example github url, to help communicate precisely what's wanted. * Add a question about the SHA256 to make sure that submitters changing the tag can't change the binary without setting off flags.
2022-03-23Make process slightly clearerTed Brandston
Update the process described in README.md to be slightly clearer. * The checklist in the ISSUE_TEMPLATE asks for your tag, not your branch so we should match that. * "when you have accepted tag" might be ambiguous in this context. We're talking about git tags and issue tags/labels. Acceptance is indicated with a github label, so let's try to clearly state that.
2022-03-23Edit questions in README for clarity and consistencyTed Brandston
Changes to: * Formatting * Capitalization * Sentence structure, where appropriate * Question-ifying (please confirm [...]. -> Do you [...]?) I had a hard time understanding a few of the questions, and spent some time looking through the history to understand when they were added and how they evolved. Some of them were phased differently between ISSUE_TEMPLATE and README, so when in doubt I've erred on the side of keeping more detailed versions of questions.
2022-02-10Move all questions from ISSUE_TEMPLATE to READMETed Brandston
This is a bit of a workflow change. Based on the conversation in https://github.com/rhboot/shim-review/pull/207, seems like the README should be the source of truth for submissions. I've tried to remove duplicates. When in doubt I've used the history to see what questions were added at the same time and considered similar-but-different phrasing to be "duplicated". For now all added questions have been tacked on the end. Grouping by subject can come later.
2022-02-10Improve grammar/consistency in README and ISSUE_TEMPLATETed Brandston
This is almost entirely changes to capitalization, spacing, etc. There are a few places where I've added words where I felt they'd be uncontroversial.
2022-02-10Make formatting of README and ISSUE_TEMPLATE matchTed Brandston
This changes the headers and horizontal rules to be the same style in both documents. This makes it a little easier for submitters to copy answers from one to the other, and hopefully easier for maintainers to update the questions (only one format to manage).
2021-12-07Include question about signed grub binary compositionJulian Andres Klode
2021-12-07README: clarify PGP requirementsRobbie Harwood
This attempts to fix two problems: first, that pgp.mit.edu isn't reliable enough to regularly use, and second that we're getting shim review requests are not providing the information we need to verify emails. Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2021-12-06Ask submissions to preserve upstream SBAT entries in derivativesJulian Andres Klode
2021-10-26Add code of conductRobbie Harwood
This is the standard Contributor Covenant. See-also: https://www.contributor-covenant.org/ Signed-off-by: Robbie Harwood <rharwood@redhat.com>
2021-09-28Minor typosmikebeaton
2021-04-16Require a Dockerfile to reproduce the provided shim EFI binariesJavier Martinez Canillas
Signed-off-by: Javier Martinez Canillas <javierm@redhat.com>
2021-03-31Point to shim-15.4 sourceChris Co
Shim-15.3 should not be used. Point to shim-15.4 release instead. Signed-off-by: Chris Co <chrco@microsoft.com>