spockframework / spockframework/spock

Confirm officials signing keys correlation to core developer

Open
#989 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Java
Stars
3.6k
Forks
483
PR merge metrics
No merged PRs in 30d

Description

In respect to #984 it would be good to confirm that mentioned signing keys are provided by the Spock core developer(s).

It could be done for example by adding/modifying them in a commit signed itself by the private key of the core developer which in turn is associated to him (or his public acocunts) using https://keybase.io/ or some f2f meeting.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review issue #984 and locate where the mentioned signing keys are documented or used. Determine how a signed commit and the proposed Keybase or face-to-face identity evidence would establish the keys' association with Spock core developers; done means that association is documented and verifiable.

Written by the indexing model from the issue text.

Assessment

Tech stack
git
Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.