raboof opened a new pull request, #2530:
URL: https://github.com/apache/pekko/pull/2530

   This key was generated by Infra to allow staging releases from CI. This 
request was tracked as https://issues.apache.org/jira/browse/INFRA-27312
   
   As per the [ASF Release 
Policy](https://www.apache.org/legal/release-policy.html#owned-controlled-hardware),
 artifacts signed with this key should never be automatically published to 
user-facing location, but always first published to a staging area, verified 
(typically by the PMC), and then promoted (typically by the RM). This is 
already part of our [release 
process](https://github.com/apache/pekko-site/wiki/Pekko-Release-Process)
   
   No human should have access to the corresponding private key. If we ever 
have reason to believe this key was compromised, the PMC has access to a 
corresponding revocation key.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to