EsotericSoftware / EsotericSoftware/minlog
Add key to PGP keys map
Open
- Dominant language
- Java
- Stars
- 177
- Forks
- 33
- PR merge metrics
- No merged PRs in 30d
Description
Maven Central requires all published artifacts to be [signed using PGP](https://maven.apache.org/repository/guide-central-repository-upload.html#pgp-signature). If a publisher provides their key ID to [PGP keys map](https://github.com/s4u/pgp-keys-map) then end users can use the [Verify PGP signatures plugin](https://github.com/s4u/pgpverify-maven-plugin) to validate that the artifact has not been altered or replaced as part of a supply-chain attack.
Contributor guide
Assessment
This issue has not been assessed yet.