element-hq / element-hq/synapse
Document gpg keys used for releases
- Dominant language
- Python
- Stars
- 4.6k
- Forks
- 607
- Avg merge
- 5d 22h
- Merged PRs (30d)
- 51
Description
This issue has been migrated from [#15994](https://github.com/matrix-org/synapse/issues/15994).
---
**Description:**
Hello! I'd like to be able to, e.g., `git verify-tag v1.88.0`, but I can't find any keys corresponding public key with that fingerprint posted anywhere. There's also no email for that key. Also, releases seem to be signed by one of at least several people.
Would it be possible to sign with a single key, or at least provide a keyring with all authorized signers?
Contributor guide
Research direction
Start by reviewing the release-signing process and run `git verify-tag v1.88.0` to inspect the current signature. Document the fingerprints and contact details for authorized release signers, or provide a keyring containing them, so users can verify release tags.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- git
- Domain
- documentation, release, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100