slackapi / slackapi/java-slack-sdk

New release key not mentioned in release notes or SECURITY.md?

Open
#1,422 15 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

auto-triage-skip discussion question
Dominant language
Java
Stars
602
Forks
232
Avg merge
4d 9h
Merged PRs (30d)
7

Description

When migrating from 1.45.0 to 1.45.1 the release key changed without this being mentioned in the release notes. Is this expected?

    - On artifact slack-api-client-1.45.1.pom (com.slack.api:slack-api-client:1.45.1) in repository 'MavenRepo': 
      Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
    - On artifact slack-api-client-kotlin-extension-1.45.1.pom (com.slack.api:slack-api-client-kotlin-extension:1.45.1) in repository 'MavenRepo':
      Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
    - On artifact slack-api-model-1.45.1.pom (com.slack.api:slack-api-model:1.45.1) in repository 'MavenRepo': 
      Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
    - On artifact slack-api-model-kotlin-extension-1.45.1.pom (com.slack.api:slack-api-model-kotlin-extension:1.45.1) in repository 'MavenRepo': 
      Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
    - On artifact slack-sdk-parent-1.45.1.pom (com.slack.api:slack-sdk-parent:1.45.1) in repository 'MavenRepo': 
      Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified

(I'm saving keys locally, thus the comment about not found on key server)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the release notes for 1.45.1 and SECURITY.md, then read the issue discussion to determine whether the signing-key change was expected and what public key details should be documented. Done means the key transition and verification guidance are accurately recorded in the relevant documentation.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
documentation, release, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.