-
Notifications
You must be signed in to change notification settings - Fork 923
Document GPG signing key #7783
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Document GPG signing key #7783
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #7783 +/- ##
=========================================
Coverage 90.17% 90.17%
Complexity 7189 7189
=========================================
Files 814 814
Lines 21730 21730
Branches 2129 2129
=========================================
Hits 19594 19594
Misses 1467 1467
Partials 669 669 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
|
||
| ### Verifying Artifacts | ||
|
|
||
| All artifacts published to Maven Central are signed with GPG key [`17A27CE7A60FF5F0`](https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x17A27CE7A60FF5F0) (fingerprint: `3F05 DDA9 F317 301E 9271 36D4 17A2 7CE7 A60F F5F0`). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Still need to do some homework to understand attestations, but if I recall correctly, they won't change / impact how we sign artifacts for things from opentelemetry-java because they only apply to "distributions" (i.e. not library artifacts). Is that right?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
not fully sure myself, but the way I'm seeing attestations used currently is on artifacts attached to github releases
jack-berg
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
Resolves #7689