Regarding PGP key documentation #116
-
Hi team, We use Dependency Verification and I was unable to find any documentation stating which keys are safe Could you please document the PGP keys that are used for your releases? Here are some examples of other projects documenting what key they use to sign their artifacts. https://github.com/qos-ch/slf4j/blob/master/SECURITY.md#verifying-contents As an example, With the following information:
If you have an existing documentation about this, please let me know :) |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 6 replies
-
@cowtowncoder Do you happen to know about this? As the key belongs to you supposedly |
Beta Was this translation helpful? Give feedback.
-
Maybe https://github.com/FasterXML/jackson/blob/master/KEYS ? |
Beta Was this translation helpful? Give feedback.
Maybe
https://github.com/FasterXML/jackson/blob/master/KEYS
?