EsotericSoftware / EsotericSoftware/minlog

Add key to PGP keys map

Open
#14 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
177
Forks
33
PR merge metrics
No merged PRs in 30d

Description

Maven Central requires all published artifacts to be [signed using PGP](https://maven.apache.org/repository/guide-central-repository-upload.html#pgp-signature). If a publisher provides their key ID to [PGP keys map](https://github.com/s4u/pgp-keys-map) then end users can use the [Verify PGP signatures plugin](https://github.com/s4u/pgpverify-maven-plugin) to validate that the artifact has not been altered or replaced as part of a supply-chain attack.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.