Fix Alpine GPG verification failures and support multiple keys - #1262
Conversation
…ation failures. To prevent build failures due to missing GPG or rotated vendor keys. Also allow multiple GPG keys to be provided.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Microsoft signature verification should short-circuit cleanly when gpg is unavailable (matching Temurin) to avoid misleading warnings and unnecessary work in Alpine-like environments.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Lite
Findings: 1
New issues introduced by this change (1)
| Severity | Finding |
|---|---|
src/distributions/microsoft/installer.ts — Signature verification for Microsoft builds doesn’t check whether gpg is available before… |
What changed in this PR
Updates signature verification behavior to avoid Alpine (musl) workflow failures by defaulting to “check and warn” (non-fatal) while still allowing users to explicitly enforce signature verification, and expands key handling to support multiple GPG keys.
Changes:
- Add an explicit “enforced vs check-and-warn vs disabled” verification policy and incorporate it into JDK cache identity keys.
- Support multiple signature verification keys (type + import path), and improve warning/error messaging with recovery guidance.
- Update docs, action metadata, compiled
dist/bundles, and tests to match the new verification semantics.
| File | Description |
|---|---|
| src/jdk-cache.ts | Expands verification identity to include enforcement policy and fingerprint multiple-key inputs. |
| src/gpg.ts | Adds isGpgAvailable() and allows importing multiple public keys for signature verification. |
| src/distributions/temurin/installer.ts | Restores default warning-only behavior; enforces failures only when explicitly requested; checks for gpg availability. |
| src/distributions/microsoft/installer.ts | Switches default behavior to warning-only unless explicitly requested; adds key-rotation guidance to failures. |
| src/distributions/local/installer.ts | Updates cache identity call signature for new verification identity parameters. |
| src/distributions/base-models.ts | Introduces SignatureVerificationKey and uses it for installer options. |
| src/distributions/base-installer.ts | Tracks whether verification was explicitly requested and feeds that into cache identity and enforcement behavior. |
| src/constants.ts | Adds documentation URL and standardized “recovery guidance” help text for verification failures. |
| README.md | Documents new default vs enforced verification behavior and multi-key configuration guidance. |
| docs/advanced-usage.md | Documents cache key separation across verification modes and key sets. |
| action.yml | Updates input descriptions to reflect new default/warn vs explicit/enforced behavior and multi-key support. |
| tests/jdk-cache.test.ts | Updates and expands coverage for verification policy/key separation in cache identities. |
| tests/gpg.test.ts | Adds coverage for importing multiple keys. |
| tests/distributors/temurin-installer.test.ts | Adds coverage for implicit vs explicit verification behavior and gpg availability handling. |
| tests/distributors/microsoft-installer.test.ts | Adds coverage for warning-only default behavior and enforced failure behavior. |
| tests/distributors/local-installer.test.ts | Updates expected verification identity from unverified to disabled. |
| tests/distributors/base-installer.test.ts | Updates mocks/expectations for new verification identity signature and default identity value. |
| tests/cleanup-java.test.ts | Updates expected verification identity from unverified to disabled. |
| dist/setup/index.js | Updates bundled constants exports for signature verification help text. |
| dist/setup/81.index.js | Updates bundled GPG helpers to support multiple keys and isGpgAvailable(). |
| dist/setup/779.index.js | Updates bundled cache identity logic for policy + multi-key fingerprinting. |
| dist/setup/463.index.js | Updates bundled Temurin behavior for warn-by-default and explicit enforcement. |
| dist/setup/242.index.js | Updates bundled base installer to track explicit verification requests and new cache identity signature. |
| dist/setup/220.index.js | Updates bundled Microsoft behavior for warn-by-default and explicit enforcement. |
| dist/setup/19.index.js | Updates bundled Local distribution cache identity call signature. |
| dist/cleanup/index.js | Updates bundled constants and GPG helpers to match runtime behavior. |
| dist/cleanup/314.index.js | Updates bundled cache identity logic for policy + multi-key fingerprinting. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.7.0 to 6.0.1. Release notes *Sourced from [actions/setup-java's releases](https://github.com/actions/setup-java/releases).* > v6.0.1 > ------ > > What's Changed > -------------- > > * Fix failing GitHub Actions job for temurin 17 by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1259](https://redirect.github.com/actions/setup-java/pull/1259) > * Fix Temurin EA E2E signature verification by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1260](https://redirect.github.com/actions/setup-java/pull/1260) > * Fix Alpine GPG verification failures and support multiple keys by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1262](https://redirect.github.com/actions/setup-java/pull/1262) > * Fix import-safe checks when scripts are run from a path with symlinks by [`@otaconix`](https://github.com/otaconix) in [actions/setup-java#1265](https://redirect.github.com/actions/setup-java/pull/1265) > * Avoid macOS GPG socket overflow on long runner paths by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1266](https://redirect.github.com/actions/setup-java/pull/1266) > * Complete v6 release highlights in README by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1254](https://redirect.github.com/actions/setup-java/pull/1254) > * Group and slow routine Dependabot updates by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1255](https://redirect.github.com/actions/setup-java/pull/1255) > * chore(deps-dev): update eslint and globals by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1256](https://redirect.github.com/actions/setup-java/pull/1256) > > New Contributors > ---------------- > > * [`@otaconix`](https://github.com/otaconix) made their first contribution in [actions/setup-java#1265](https://redirect.github.com/actions/setup-java/pull/1265) > > **Full Changelog**: <actions/setup-java@v6.0.0...v6.0.1> > > v6.0.0 > ------ > > What's Changed > -------------- > > * dist: Migrate from Zulu Discovery API to Azul Metadata API by [`@jameswald`](https://github.com/jameswald) in [actions/setup-java#1010](https://redirect.github.com/actions/setup-java/pull/1010) > * feat: add .mvn/extensions.xml to Maven cache key pattern by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1041](https://redirect.github.com/actions/setup-java/pull/1041) > * Migrate to ESM and upgrade dependencies by [`@priyagupta108`](https://github.com/priyagupta108) in [actions/setup-java#1078](https://redirect.github.com/actions/setup-java/pull/1078) > * Map Zulu x86 architecture to i686 for Azul Metadata API by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1079](https://redirect.github.com/actions/setup-java/pull/1079) > * Rename jdkFile input to jdk-file with deprecated alias by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1083](https://redirect.github.com/actions/setup-java/pull/1083) > * Infer distribution from asdf .tool-versions vendor prefix by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1084](https://redirect.github.com/actions/setup-java/pull/1084) > * Add Maven compiler problem matcher for javac diagnostics by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1086](https://redirect.github.com/actions/setup-java/pull/1086) > * feat: expose cache-primary-key output ([#597](https://redirect.github.com/actions/setup-java/issues/597)) by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1088](https://redirect.github.com/actions/setup-java/pull/1088) > * docs: clarify V6 ESM migration is not a user-facing breaking change by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1090](https://redirect.github.com/actions/setup-java/pull/1090) > * Support multi-field Java versions like `18.0.1.1` by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1092](https://redirect.github.com/actions/setup-java/pull/1092) > * docs: document seeding the Maven cache for plugin dependencies by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1094](https://redirect.github.com/actions/setup-java/pull/1094) > * docs: clarify Maven cache paths and key hash inputs by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1096](https://redirect.github.com/actions/setup-java/pull/1096) > * Support pinning java-version as "latest" by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1093](https://redirect.github.com/actions/setup-java/pull/1093) > * chore(deps-dev): bump eslint from 10.6.0 to 10.7.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1101](https://redirect.github.com/actions/setup-java/pull/1101) > * chore(deps-dev): bump eslint-plugin-n from 18.2.1 to 18.2.2 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1103](https://redirect.github.com/actions/setup-java/pull/1103) > * chore(deps-dev): bump prettier from 3.9.4 to 3.9.5 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1105](https://redirect.github.com/actions/setup-java/pull/1105) > * chore(deps): bump actions/checkout from 6 to 7 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1106](https://redirect.github.com/actions/setup-java/pull/1106) > * chore(deps-dev): bump `@types/node` from 26.1.0 to 26.1.1 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1104](https://redirect.github.com/actions/setup-java/pull/1104) > * dist: Cover Tencent Kona JDK 25 by [`@johnshajiang`](https://github.com/johnshajiang) in [actions/setup-java#1108](https://redirect.github.com/actions/setup-java/pull/1108) > * chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1102](https://redirect.github.com/actions/setup-java/pull/1102) > * Preserve Maven toolchains across repeated setup-java runs ([#1099](https://redirect.github.com/actions/setup-java/issues/1099)) by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1111](https://redirect.github.com/actions/setup-java/pull/1111) > * dist: Support Liberica NIK ([#878](https://redirect.github.com/actions/setup-java/issues/878)) by [`@asm0dey`](https://github.com/asm0dey) in [actions/setup-java#1112](https://redirect.github.com/actions/setup-java/pull/1112) > * Fix template injection (zizmor alert [#118](https://redirect.github.com/actions/setup-java/issues/118)) in e2e-versions.yml by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1114](https://redirect.github.com/actions/setup-java/pull/1114) > * Fix template injection in e2e-versions.yml (zizmor alert [#122](https://redirect.github.com/actions/setup-java/issues/122)) by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1120](https://redirect.github.com/actions/setup-java/pull/1120) > * Disable persisted checkout credentials in e2e workflow by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1115](https://redirect.github.com/actions/setup-java/pull/1115) > * feat: Update recommended configuration for GPG signing by [`@wetneb`](https://github.com/wetneb) in [actions/setup-java#608](https://redirect.github.com/actions/setup-java/pull/608) > * Cache Maven and Gradle wrapper distributions separately from the dependency cache by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1097](https://redirect.github.com/actions/setup-java/pull/1097) > * Consolidate cache-dependency-path e2e workflow and add maven/sbt coverage by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1124](https://redirect.github.com/actions/setup-java/pull/1124) > * Use gpg.passphraseEnvName instead of the deprecated gpg.passphrase server by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1123](https://redirect.github.com/actions/setup-java/pull/1123) > * Extract repeated directory-check assertions into check-dir.sh helper by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1127](https://redirect.github.com/actions/setup-java/pull/1127) > * Consolidate duplicate jobs in e2e-versions workflow by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1125](https://redirect.github.com/actions/setup-java/pull/1125) > * Use YAML anchors to reduce boilerplate in e2e-versions workflow by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1126](https://redirect.github.com/actions/setup-java/pull/1126) ... (truncated) Commits * [`de7274f`](actions/setup-java@de7274f) Avoid macOS GPG socket overflow on long runner paths ([#1266](https://redirect.github.com/actions/setup-java/issues/1266)) * [`134912a`](actions/setup-java@134912a) Fix import-safe checks when scripts are run from a path with symlinks ([#1265](https://redirect.github.com/actions/setup-java/issues/1265)) * [`0781fc6`](actions/setup-java@0781fc6) Fix alpine failures by switching default back to only warn on verification fa... * [`4889c4a`](actions/setup-java@4889c4a) Fix Temurin EA E2E signature verification ([#1260](https://redirect.github.com/actions/setup-java/issues/1260)) * [`8fd3240`](actions/setup-java@8fd3240) [WIP] Fix failing GitHub Actions job for temurin 17 ([#1259](https://redirect.github.com/actions/setup-java/issues/1259)) * [`2732291`](actions/setup-java@2732291) chore(deps-dev): update eslint and globals ([#1256](https://redirect.github.com/actions/setup-java/issues/1256)) * [`1a8f22b`](actions/setup-java@1a8f22b) chore: streamline Dependabot updates ([#1255](https://redirect.github.com/actions/setup-java/issues/1255)) * [`85030b7`](actions/setup-java@85030b7) docs: complete v6 release highlights ([#1254](https://redirect.github.com/actions/setup-java/issues/1254)) * [`dd06d9c`](actions/setup-java@dd06d9c) Prepare documentation for v6 release ([#1253](https://redirect.github.com/actions/setup-java/issues/1253)) * [`59b3450`](actions/setup-java@59b3450) chore(deps): combine open Dependabot npm updates ([#1252](https://redirect.github.com/actions/setup-java/issues/1252)) * Additional commits viewable in [compare view](actions/setup-java@b6effb0...de7274f) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary
mainat4889c4aff54cecfc8d479c505d9893fd814df73f.[email protected]).Validation
npm run check