Hi Torsten,

I actually added my code signing key in https://svn.apache.org/repos/asf/cocoon/branches/BRANCH_2_1_X/KEYS

I wasn't aware of https://downloads.apache.org/cocoon/KEYS. I'll add my key to this file when uploading release artifacts.

Is it ok for you ?

Cédric


Le 19/07/2020 à 19:18, Torsten Curdt a écrit :
I did a

  gpg --import KEYS.txt

just to make sure, but I am still getting

  gpg --verify cocoon-2.1.13-src.tar.gz.asc cocoon-2.1.13-src.tar.gz
  gpg: Signature made Fr 17 Jul 20:05:16 2020 CEST
  gpg:                using RSA key F9E031E290C9797C7F4CC02576ABEF9A6CDA1E88
  gpg: Can't check signature: No public key

Is your key maybe missing from https://downloads.apache.org/cocoon/KEYS

cheers,
Torsten

On Sat, Jul 18, 2020 at 7:08 AM Francesco Chicchiriccò <ilgro...@apache.org <mailto:ilgro...@apache.org>> wrote:

    On 17/07/20 20:40, Cédric Damioli wrote:
    > Hi,
    >
    > More than 7 years after the 2.1.12 release, I'm glad to propose
    to release Apache Cocoon 2.1.13 !
    >
    > Proposed releases artifacts are located at
    https://dist.apache.org/repos/dist/dev/cocoon/
    >
    > Please check the files, verify checksums, build and run samples,
    and cast your votes.

    +1
    Thanks Cédric!

    Regards.

-- Francesco Chicchiriccò

    Tirasa - Open Source Excellence
    http://www.tirasa.net/

    Member at The Apache Software Foundation
    Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail
    http://home.apache.org/~ilgrosso/


--
Cédric Damioli
CMS - Java - Open Source
www.ametys.org

Reply via email to