slachiewicz opened a new pull request, #339: URL: https://github.com/apache/maven-gpg-plugin/pull/339
#337 fails `pgpverify` because junixsocket rotated its signing key: 2.10.1 is signed by `29B8FEA02804261C`, 2.11.0 by `0321BEE8AA36B734`. The artifacts are signed — the map simply does not know the new key. Both keys are kept, in the same comma form already used for `commons-io`, so the map is valid whether or not #337 lands. Provenance of the new key, for the reviewer to check independently: full fingerprint `F2F098DD0383FE75CD5C6D3A0321BEE8AA36B734`, EdDSA, created 2024-12-04, expires 2027-12-03, published on keys.openpgp.org with the verified UID `Christian Kohlschütter <[email protected]>` — the junixsocket maintainer, matching the `com.kohlschutter` groupId. *This change was created with AI assistance.* -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
