dave2wave commented on issue #180: URL: https://github.com/apache/tooling-trusted-releases/issues/180#issuecomment-4789969181
We should defer the expired keys question. For this issue it is a simple question of the UX we have the ability to delete a key and if the reference count of signed artifacts is greater than zero simply block deletion. A side issue is if the key was used for releases of a PMC then block it from being disassociated. This may be the hard one. Figure that out and we will create an issue about populating in the catalog track. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
