element-hq / element-hq/synapse

Document gpg keys used for releases

Open
#15,994 1 comment 0 reactions 0 assignees View on GitHub
A-Docs O-Uncommon S-Tolerable T-Other
Dominant language
Python
Stars
4.6k
Forks
607
Avg merge
5d 22h
Merged PRs (30d)
51

Description

This issue has been migrated from [#15994](https://github.com/matrix-org/synapse/issues/15994).

---

**Description:**

Hello! I'd like to be able to, e.g., `git verify-tag v1.88.0`, but I can't find any keys corresponding public key with that fingerprint posted anywhere. There's also no email for that key. Also, releases seem to be signed by one of at least several people.

Would it be possible to sign with a single key, or at least provide a keyring with all authorized signers?

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the release-signing process and run `git verify-tag v1.88.0` to inspect the current signature. Document the fingerprints and contact details for authorized release signers, or provide a keyring containing them, so users can verify release tags.

Written by the indexing model from the issue text.

Assessment

Tech stack
git
Domain
documentation, release, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.