ppkarwasz opened a new issue, #170: URL: https://github.com/apache/tooling-trusted-release/issues/170
Log4j releases are built using GitHub Actions, which results in the following ATR error: > `Verifying key lacks an ASF UID` This is expected, as GitHub Actions does not use a key tied to an ASF UID — it's an automated workflow. While we may eventually include *in-toto* attestations to capture the triggering user's identity, what’s the recommended workaround for this scenario? Can ATR support trusted CI keys or allow an override for automated builds in the meantime? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tooling.apache.org.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tooling.apache.org For additional commands, e-mail: dev-h...@tooling.apache.org