dave2wave commented on issue #180:
URL: 
https://github.com/apache/tooling-trusted-releases/issues/180#issuecomment-4789969181

   We should defer the expired keys question. For this issue it is a simple 
question of the UX we have the ability to delete a key and if the reference 
count of signed artifacts is greater than zero simply block deletion.
   
   A side issue is if the key was used for releases of a PMC then block it from 
being disassociated. This may be the hard one. Figure that out and we will 
create an issue about populating in the catalog track.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to