jakartaee / jakartaee/validation

PGP key cannot be verified because it is not published on the GitHub page

Open
#325 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
163
Forks
67
Avg merge
3d 15h
Merged PRs (30d)
2

Description

This library causes problems with Gradle dependency verification. The libraries are signed and the key is available on hkps://keyserver.ubuntu.com, but it is self-signed and not listed on the GitHub page.

If you would publish the key on GitHub then users could verify that the libraries are actually signed with your key.

Contributor guide

Open the contributing guide

Research direction

Start by checking the repository's GitHub page and any release or signing guidance for where the project's PGP key is published. Confirm the key available from keyserver.ubuntu.com and make it available on GitHub so users can verify signed Gradle dependencies.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, java
Domain
release, security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.