• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

letsencrypt / pebble / 36477763631
9%
master: 8%

Build:
Build:
LAST BUILD BRANCH: main
DEFAULT BRANCH: master
Ran 28 Sep 2026 08:15PM UTC
Jobs 1
Files 18
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 08:14PM UTC coverage: 9.477% (+0.2%) from 9.243%
36477763631

push

github

web-flow
Normalize the serial in NewCertID so ARI replaces lookups match (#556)

When a certificate's serial starts with a byte >= 0x80, ACME clients put
an extra `00` in front of it in the ARI certID. That's correct, since
RFC 9773 asks for the DER integer bytes. But Pebble stores issued
certificates under the serial without that `00`, so a new order with
`replaces` for one of those certificates can't find the original and
fails with a 500. This happens for about 1 in 256 certificates.

The fix builds the certID's lookup key from the parsed number instead of
the raw bytes, so both forms give the same key. This is the same way the
certificate is stored in `ca.go`, and the renewalInfo endpoint already
looks things up this way.

Fixes https://github.com/letsencrypt/pebble/issues/550

3 of 3 new or added lines in 1 file covered. (100.0%)

442 of 4664 relevant lines covered (9.48%)

1.71 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36477763631.1 28 Sep 2026 08:15PM UTC 18
9.48
GitHub Action Run
Source Files on build 36477763631
  • Tree
  • List 18
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 1fcb30ca on github
  • Prev Build on main (#35784676080)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc