fix(node): Use dl.yarnpkg.com for Yarn GPG key on all Debian versions#1547
fix(node): Use dl.yarnpkg.com for Yarn GPG key on all Debian versions#1547abdurriq merged 4 commits intodevcontainers:mainfrom
Conversation
Branch-Creation-Time: 2026-01-29T00:16:22+0000
Kaniska244
left a comment
There was a problem hiding this comment.
Thank you for the fix. Would you kindly bump up the node feature version to 1.6.5?
|
Can you please speed this up a bit? I'm currently pretty much blocked since all of my devcontainers refuse to build due to this issue. @Kaniska244 I love updates. But please don't mix them with critical bugfixes in the same PR. |
Hi @max06 Request you to follow this issue for updates and workaround. |
yep! Done. Please let me know if anything else needs to be modified. Thanks! |
|
@microsoft-github-policy-service agree |
Hi @Kaniska244 I'm aware of that workaround. But since I'm using the image as an image in my devcontainers and not as base in a local dockerfile, I can't apply the workarounds there. That's why I need that updated image. |
|
Quick check on this. Are we able to get this merged or does it need some additional things? |
GPG key has expired so the container build fails with this enabled. Waiting on devcontainers/features#1547 and devcontainers/images#1752
Problem
Yarn rotated their signing key on 2026-01-28. The previous fix (#1546) for Debian trixie
fetched the key from
keys.openpgp.orgusing a specific fingerprint, but that sourceonly has the old key.
Additionally, the old signing subkeys expired on 2026-01-23, breaking all existing
installations that haven't refreshed their keys.
Solution
dl.yarnpkg.com/debian/pubkey.gpgfor all Debian versions/etc/apt/keyrings/as the keyring location (modern standard)Verification