slackapi / slackapi/java-slack-sdk
New release key not mentioned in release notes or SECURITY.md?
Open
Nobody has claimed this yet.
auto-triage-skip
discussion
question
- Dominant language
- Java
- Stars
- 602
- Forks
- 232
- Avg merge
- 4d 9h
- Merged PRs (30d)
- 7
Description
When migrating from 1.45.0 to 1.45.1 the release key changed without this being mentioned in the release notes. Is this expected?
- On artifact slack-api-client-1.45.1.pom (com.slack.api:slack-api-client:1.45.1) in repository 'MavenRepo':
Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
- On artifact slack-api-client-kotlin-extension-1.45.1.pom (com.slack.api:slack-api-client-kotlin-extension:1.45.1) in repository 'MavenRepo':
Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
- On artifact slack-api-model-1.45.1.pom (com.slack.api:slack-api-model:1.45.1) in repository 'MavenRepo':
Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
- On artifact slack-api-model-kotlin-extension-1.45.1.pom (com.slack.api:slack-api-model-kotlin-extension:1.45.1) in repository 'MavenRepo':
Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
- On artifact slack-sdk-parent-1.45.1.pom (com.slack.api:slack-sdk-parent:1.45.1) in repository 'MavenRepo':
Artifact was signed with key '8E05CCB0D18336A9' but it wasn't found in any key server so it couldn't be verified
(I'm saving keys locally, thus the comment about not found on key server)
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the release notes for 1.45.1 and SECURITY.md, then read the issue discussion to determine whether the signing-key change was expected and what public key details should be documented. Done means the key transition and verification guidance are accurately recorded in the relevant documentation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- documentation, release, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100