Skip to content

[aws-cli] Change dependency from gnupg2 to gpg #1360

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

eszense
Copy link

@eszense eszense commented May 15, 2025

Currently the aws-cli feature installs gnupg2 for verifying aws-cli signature
However, gnupg2 package install a few other utilities besidesgpg. Only gpg package is required for signature verification, the other components are reductant.

Using gpg as the dependency improves install speed, save disk space for automated workflow, and more importantly reduces the attack surface of minimal systems.

Other components of gnupg2 are not necessary for verifying the aws-cli signature.
@eszense eszense requested a review from a team as a code owner May 15, 2025 15:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant