sbp commented on issue #180: URL: https://github.com/apache/tooling-trusted-releases/issues/180#issuecomment-4789876774
We can only delete unexpired keys when we have the complete set of signatures, so we need to collect that from attic and svn. But what about expired keys? In my local test instance, I have 2666 signing keys of which 446 (~16.7%) are expired. What is our policy in ATR about expired keys? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
