https://bz.apache.org/bugzilla/show_bug.cgi?id=70200
--- Comment #2 from Stefan Bodewig <[email protected]> --- Thank you for verifying the signature. I completely agree with your reasons for doing so. I have just downloaded ant-1.10.17.jar and the corresponding signature from Maven Central: $ LC_ALL=C gpg --verify ant-1.10.17.jar.asc gpg: assuming signed data in 'ant-1.10.17.jar' gpg: Signature made Mon Apr 6 11:16:12 2026 CEST gpg: using EDDSA key 6A93161EB1990E8346E7BA2B23738DFD7C40DE43 gpg: issuer "[email protected]" gpg: Good signature from "Stefan Bodewig <[email protected]>" [ultimate] the ultimate trust is bcause it is my key, of course. 6A93161EB1990E8346E7BA2B23738DFD7C40DE43 is one of the two signing subkeys of BC26C53AF531F8B4B3F5930AAFBD3AF8EAFA72DA which is the next to last entry in https://downloads.apache.org/ant/KEYS -- You are receiving this mail because: You are the assignee for the bug.
