Skip to content

[Bug]: Linux Development snapshots are not signed #681

@birdie-github

Description

@birdie-github

Version

trunk/main

Host OS Type

Linux

Component

Host Installer

What happened?

I don't feel comfortable downloading and using them.

What if they contain malicious code from God knows whom?

How can we reproduce this?

rpm -K VirtualBox-7.2-7.2.97_173998_el10-1.x86_64.rpm 
VirtualBox-7.2-7.2.97_173998_el10-1.x86_64.rpm: digests OK

instead it must say:

digests signatures OK

Secondly,

Name        : VirtualBox-7.2
Version     : 7.2.97_173998_el10
Release     : 1
Architecture: x86_64
Install Date: (not installed)
Group       : Applications/System
Size        : 290619845
License     : GPLv3
Signature   : (none)
Source RPM  : VirtualBox-7.2-7.2.97_173998_el10-1.src.rpm
Build Date  : Fri 22 May 2026 05:18:04 PM UTC
Build Host  : 66abc21b41bc
Vendor      : Oracle Corporation
URL         : http://www.virtualbox.org/
Summary     : Oracle VirtualBox

What's up with the Build Host? Can we have something meaningful?

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions