Replies: 1 comment 2 replies
-
You are not missing anything on your side.The signature is valid, but the signing key was already expired at the time the artifact was published, which is why GPG reports a good signature from an expired key. In this situation, there is no βupdated versionβ of the same key available on keyservers. Important points to clarify:
What needs to happen to fix this properly:
What cannot be fixed:
So the correct resolution is indeed for the project maintainer to publish a new signing key and use it for future releases. Until then, consumers must either accept the expired key (if policy allows) or treat the artifact as unverifiable. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
07EE2908793B6EAD3EC35AAFB453979C79892013 was used to sign
com/graphql-java/graphql-java/25.0/graphql-java-25.0.jarbut the published key expired by then:and none of
has updated version of said key.
Could the updated key be sent to some keyservers, please?
Beta Was this translation helpful? Give feedback.
All reactions