Rafael Winterhalter created VELOCITY-1002:
---------------------------------------------

             Summary: KEYS file does not list the key that signed the 2.4.1 
release
                 Key: VELOCITY-1002
                 URL: https://issues.apache.org/jira/browse/VELOCITY-1002
             Project: Velocity
          Issue Type: Wish
            Reporter: Rafael Winterhalter


The 2.4.1 release artifacts are signed with OpenPGP key 
6F9D10E747DC79485ABB4F72B709E61252F136DD (Claude Brisson, 
<[email protected]>): the source and binary distributions under 
https://downloads.apache.org/velocity/engine/2.4.1/ and the Maven artifacts of 
org.apache.velocity:velocity-engine-core:2.4.1 on Central carry signatures by 
that key.

https://downloads.apache.org/velocity/KEYS does not contain it. It lists two of 
the release manager's keys (AE4C69EC from 2009 and BEFEEF227A98B809 from 2016), 
and the key is not on https://people.apache.org/keys/committer/cbrisson.asc 
either. Anyone verifying the release as the ASF release documentation describes 
(import KEYS, then gpg --verify) gets "no public key" for 2.4.1.

The signature itself verifies once the key is fetched from a keyserver, and the 
signer is the release manager, so this is the published KEYS file lagging the 
key in use rather than a problem with the release. Note that the key expired on 
2025-09-10; the 2.4.1 signatures predate that (2024-10-14), but a future 
release will need a current key in KEYS as well.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to