Independent verification of reproducible builds

2024-03-28 Thread Railean, Alexander
Hi everyone, I followed the instructions in guides/mini/guide-reproducible-builds.html and was able to produce a reproducible build, which I can later verify on my own system. My intention is to publish this on Maven Central and provide enough information for anyone else to be able to

RE: How to use a different signing mechanism with maven-gpg-plugin

2023-02-20 Thread Railean, Alexander
Tamás, Martin - thank you for your quick feedback. It gave me certainty that the objective can be accomplished. > if you can use your GPG CLI with your HSM, this could or should be possible, > as maven-gpg-plugin really just invokes the CLI (the gpg executable). The HSM doesn't provide such an

How to use a different signing mechanism with maven-gpg-plugin

2023-02-15 Thread Railean, Alexander
Hi everyone, I am looking for a way to use maven-gpg-plugin in conjunction with a Hardware Security Module (HSM) for the process of publishing digitally signed artifacts on Maven Central. After reading the documentation I am under the impression that the plugin assumes that it has the