Dan Klco created SLING-10775:
--------------------------------

             Summary: Committers CLI Uses Missing people.apache.org Keys File
                 Key: SLING-10775
                 URL: https://issues.apache.org/jira/browse/SLING-10775
             Project: Sling
          Issue Type: Bug
          Components: Tooling
    Affects Versions: Committer CLI 1.0.0
            Reporter: Dan Klco


The PGPSignatureValidator in the committer CLI downloads the keys from 
https://people.apache.org/keys/group/sling.asc, see:
https://github.com/apache/sling-org-apache-sling-committer-cli/blob/998b654a1682cc1460d206dc4f40514995ad621e/src/main/java/org/apache/sling/cli/impl/pgp/PGPSignatureValidator.java#L97

This is not recommended as per https://people.apache.org/keys/ and it is 
currently broken as this URL returns a 404.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to