https://bz.apache.org/bugzilla/show_bug.cgi?id=70200

--- Comment #2 from Stefan Bodewig <[email protected]> ---
Thank you for verifying the signature. I completely agree with your reasons for
doing so.

I have just downloaded ant-1.10.17.jar and the corresponding signature from
Maven Central:

$ LC_ALL=C gpg --verify ant-1.10.17.jar.asc 
gpg: assuming signed data in 'ant-1.10.17.jar'
gpg: Signature made Mon Apr  6 11:16:12 2026 CEST
gpg:                using EDDSA key 6A93161EB1990E8346E7BA2B23738DFD7C40DE43
gpg:                issuer "[email protected]"
gpg: Good signature from "Stefan Bodewig <[email protected]>" [ultimate]

the ultimate trust is bcause it is my key, of course.

6A93161EB1990E8346E7BA2B23738DFD7C40DE43 is one of the two signing subkeys of
BC26C53AF531F8B4B3F5930AAFBD3AF8EAFA72DA which is the next to last entry in
https://downloads.apache.org/ant/KEYS

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to