[
https://issues.apache.org/jira/browse/DIGESTER-202?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18112082#comment-18112082
]
Rod Widdowson commented on DIGESTER-202:
----------------------------------------
In case other people fall down this rabbit hole I should also share (because I
have been looking) that both these sites need to be consulted for Apache keys.
Most are in both places, but many only turn up in one.
> Please update keys for [email protected] on
> https://home.apache.org/keys/committer/
> -------------------------------------------------------------------------------------------
>
> Key: DIGESTER-202
> URL: https://issues.apache.org/jira/browse/DIGESTER-202
> Project: Commons Digester
> Issue Type: Bug
> Affects Versions: 3.2
> Reporter: Rod Widdowson
> Priority: Minor
>
> As background our opensource project has built some defense against supply
> chain attacks [1]
> By my calculation version 3.2 is signed by key 0xCAF5EC5919FEA27D
> I can see this key here [2], but I expected to be able to see it at an
> official location [3]
> The key for [email protected] at that site appears to be unrelated [4]
> [1]
> https://shibboleth.atlassian.net/wiki/spaces/DEV/pages/3269918721/Supply+Chain+Defence+for+the+Shibboleth+Java+Products
> [2]
> https://keyserver.ubuntu.com/pks/lookup?search=0xCAF5EC5919FEA27D&fingerprint=on&op=index
> [3] https://home.apache.org/keys/committer/
> [4]
> https://keyserver.ubuntu.com/pks/lookup?search=94C3410848CF8630%20&fingerprint=on&op=index
--
This message was sent by Atlassian Jira
(v8.20.10#820010)