Title: Add info about which gpg signing keys will be used for published artifacts. · Issue #207 · java-diff-utils/java-diff-utils · GitHub
Open Graph Title: Add info about which gpg signing keys will be used for published artifacts. · Issue #207 · java-diff-utils/java-diff-utils
X Title: Add info about which gpg signing keys will be used for published artifacts. · Issue #207 · java-diff-utils/java-diff-utils
Description: Add info about which gpg signing keys will be used for published artifacts. Looks like version 4.12 was published with key D477D51812E692011DB11E66A6EA2E2BF22E0543 ? For security purposes, it would be great if you were able to publish de...
Open Graph Description: Add info about which gpg signing keys will be used for published artifacts. Looks like version 4.12 was published with key D477D51812E692011DB11E66A6EA2E2BF22E0543 ? For security purposes, it would...
X Description: Add info about which gpg signing keys will be used for published artifacts. Looks like version 4.12 was published with key D477D51812E692011DB11E66A6EA2E2BF22E0543 ? For security purposes, it would...
Opengraph URL: https://github.com/java-diff-utils/java-diff-utils/issues/207
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Add info about which gpg signing keys will be used for published artifacts.","articleBody":"### Add info about which gpg signing keys will be used for published artifacts. \n\nLooks like version 4.12 was published with key `D477D51812E692011DB11E66A6EA2E2BF22E0543` ? \n\n\nFor security purposes, it would be great if you were able to publish details (in the project docs) about gpg public keys that are \"valid\" for use when verifying signing artifacts uploaded to maven central.\n\nThis allows for \"out of band\" verification of the expected signing key. \n\nSome examples of other libs publishing their signing keys:\n\nhttps://square.github.io/okhttp/security/security/#verifying-artifacts\nhttps://docs.couchbase.com/java-sdk/current/project-docs/sdk-release-notes.html#verifying-artifacts\n\nhttps://github.com/eclipse/jetty.project/blob/jetty-10.0.x/KEYS.txt\nhttps://downloads.apache.org/commons/KEYS\nhttps://downloads.apache.org/logging/KEYS\n\nhttps://github.com/cbeust/jcommander/blob/4b97c3440347bedb79e374408b8f123cf0ff4fd4/SECURITY.md#gpg-signature-validation\n\nThese keys can be used with [Gradle \"Dependency verification\" ](https://docs.gradle.org/current/userguide/dependency_verification.html)\n\nSee example of real world usage here: \n- https://github.com/androidx/androidx/blob/androidx-main/gradle/verification-keyring.keys\n- https://github.com/androidx/androidx/blob/androidx-main/gradle/verification-metadata.xml\n","author":{"url":"https://github.com/yogurtearl","@type":"Person","name":"yogurtearl"},"datePublished":"2025-06-27T21:37:41.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/207/java-diff-utils/issues/207"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:83710dd1-00e7-2fb6-13f6-846db1456dae |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | A3D8:9F1EC:39C56D:51B56C:696A1425 |
| html-safe-nonce | 17ac89c7dd291593fb2b8b6ba1125d523eb695bae3a4d5fd5ea0e2876a9c6afc |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBM0Q4OjlGMUVDOjM5QzU2RDo1MUI1NkM6Njk2QTE0MjUiLCJ2aXNpdG9yX2lkIjoiNTMwOTQ5MTU2NDM5MDI1NzcwMSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 92ac48d3c28655748e3930cf5d99e74da317034ac3104289d9dfcc6c98d6014a |
| hovercard-subject-tag | issue:3184151653 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/java-diff-utils/java-diff-utils/207/issue_layout |
| twitter:image | https://opengraph.githubassets.com/bc333a91771645ee9e0b4ca5a384b760366b3a878c1e85a159dd46ceddb1c073/java-diff-utils/java-diff-utils/issues/207 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/bc333a91771645ee9e0b4ca5a384b760366b3a878c1e85a159dd46ceddb1c073/java-diff-utils/java-diff-utils/issues/207 |
| og:image:alt | Add info about which gpg signing keys will be used for published artifacts. Looks like version 4.12 was published with key D477D51812E692011DB11E66A6EA2E2BF22E0543 ? For security purposes, it would... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | yogurtearl |
| hostname | github.com |
| expected-hostname | github.com |
| None | 699227a00bbb7fe1eec276d2ae1c3a93068bc5ba483bd9dc4b2a27a8f4f2f595 |
| turbo-cache-control | no-preview |
| go-import | github.com/java-diff-utils/java-diff-utils git https://github.com/java-diff-utils/java-diff-utils.git |
| octolytics-dimension-user_id | 40540835 |
| octolytics-dimension-user_login | java-diff-utils |
| octolytics-dimension-repository_id | 86663812 |
| octolytics-dimension-repository_nwo | java-diff-utils/java-diff-utils |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 86663812 |
| octolytics-dimension-repository_network_root_nwo | java-diff-utils/java-diff-utils |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 7266b2d935baa1c6474b16dd9feaa5ca30607261 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width