Signing key location? #13815
Unanswered
henriquevcosta
asked this question in
Q&A
Replies: 1 comment
-
as far as I can tell we don't publish the key fingerprint or any other details in this repository cc @trask
I think using |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I see that the .asc files being uploaded with releases match a public key with a UID "OpenTelemetry Java" (fpr
3F05 DDA9 F317 301E 9271 36D4 17A2 7CE7 A60F F5F0
), but is there anything else validating that this key is really the right one?I couldn't find documentation on the process to validate integrity and origin of the released binary, so I was just manually trying to import the key and running a
gpg --verify
.Is there any better way?
Beta Was this translation helpful? Give feedback.
All reactions