ppkarwasz opened a new issue, #170:
URL: https://github.com/apache/tooling-trusted-release/issues/170

   Log4j releases are built using GitHub Actions, which results in the 
following ATR error:
   
   > `Verifying key lacks an ASF UID`
   
   This is expected, as GitHub Actions does not use a key tied to an ASF UID — 
it's an automated workflow.
   
   While we may eventually include *in-toto* attestations to capture the 
triggering user's identity, what’s the recommended workaround for this 
scenario? Can ATR support trusted CI keys or allow an override for automated 
builds in the meantime?
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@tooling.apache.org.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tooling.apache.org
For additional commands, e-mail: dev-h...@tooling.apache.org

Reply via email to