sbp commented on issue #1393:
URL: 
https://github.com/apache/tooling-trusted-releases/issues/1393#issuecomment-4982277808

   I'm splitting the changes up into separate commits. The first commit, and 
the biggest problem, is that `/downloads/` also contained `KEYS` files that 
were generated by ATR. We now have a separate issue (#1389) to make it clear 
committee by committee whether they want ATR to manage their `KEYS` files in 
`dist/release` for them, but at the moment we consider ATR to be managing all 
`KEYS` files and they get written to `dist/atr`. The first commit will change 
ATR so that e.g. links to `KEYS` files will use the canonical download URLs on 
`downloads.apache.org`. One edge case is our signature provenance API endpoint, 
which is going to continue to query ATR itself, and will not fetch a 
committee's own canonical `KEYS` file.
   
   When we implement #1389, we should think about what it would mean for a 
committee to be managing keys through ATR but not using it to write to `KEYS` 
files in SVN. It would be very easy for them to get out of sync, and perhaps 
ATR should periodically check that.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to