Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dedicated goal to check public key used for signing the attached *.asc files properly uploaded to public keyserver #75

Open
kwin opened this issue Aug 26, 2021 · 2 comments
Labels
enhancement New feature or request.

Comments

@kwin
Copy link

kwin commented Aug 26, 2021

As Sonatype requires each Maven artifact having the public key used for signing artifacts uploaded to some public keyserver (https://central.sonatype.org/publish/requirements/gpg/#distributing-your-public-key) it would be nice to check this requirement during the release of the project with a dedicated Maven plugin goal.
Not sure whether this goal would make more sense in this plugin or rather https://www.simplify4u.org/sign-maven-plugin/

@kwin kwin changed the title Dedicated goal to check public key properly uploaded to public keyserver Dedicated goal to check public key used for signing the attached *.asc files properly uploaded to public keyserver Aug 26, 2021
@slawekjaranowski slawekjaranowski transferred this issue from s4u/pgpverify-maven-plugin Aug 26, 2021
@slawekjaranowski
Copy link
Member

I was transferred issue from - pgpverify-maven-plugin I think it will be better place to discussion

@slawekjaranowski
Copy link
Member

I hope that Sonatype verifying deployed artifacts - whether they meet the requirements - if not should

plugin can also be used for another case than signing for Maven Central - so goal must be optionally

@slawekjaranowski slawekjaranowski added the enhancement New feature or request. label Sep 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request.
Development

No branches or pull requests

2 participants