Fixed
- setup: avoid local network access for application icons (#100) (03d4e8a9da92)
Verify and install
pkg checks nothing about a file handed to it directly. Establish its
GitHub/Sigstore provenance before the package reaches the firewall.
On an administrator workstation:
curl --fail --location --output /tmp/os-openid-connect-1.0.0.beta4.pkg \
https://github.com/jpawlowski/opnsense-openid-connect/releases/download/v1.0.0-beta4/os-openid-connect-1.0.0.beta4.pkg
gh attestation verify /tmp/os-openid-connect-1.0.0.beta4.pkg \
-R jpawlowski/opnsense-openid-connect \
--signer-workflow jpawlowski/opnsense-openid-connect/.github/workflows/build.yml \
--deny-self-hosted-runners
Copy that verified package to /tmp on the firewall. Confirm that the
transfer preserved its exact bytes, then install it:
sha256 -c 80afe4566b5571e1d48fddd125832e11a4f1defa3d004e8b3647b29d82aa9944 /tmp/os-openid-connect-1.0.0.beta4.pkg
pkg add /tmp/os-openid-connect-1.0.0.beta4.pkg
No restart, no service affected. Signing in locally with a username and
password is untouched; the way back is always
pkg delete os-openid-connect.
1 commit(s) since v1.0.0-beta3.
Built from 03d4e8a9da9247797fb93cff877069d380496a84.