Skip to content

Additional configuration for PGP keys to fill in missing key map entries.

Notifications You must be signed in to change notification settings

silnith-org/pgp-keys-filler

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

27 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

PGP Keys Filler

This is a temporary project to fill in missing PGP keys used to sign Maven artifacts that are used as part of the build toolchain. This is only a temporary measure while attempting to contact and convince publishers of key Maven artifacts to add their PGP key IDs to the PGP keys map project.

Issue Template

Add key to PGP keys map

Maven Central requires all published artifacts to be signed using PGP. If a publisher provides their key ID to PGP keys map then end users can use the Verify PGP signatures plugin to validate that the artifact has not been altered or replaced as part of a supply-chain attack.

About

Additional configuration for PGP keys to fill in missing key map entries.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages