Replies: 1 comment 2 replies
-
You are not missing anything on your side.The signature is valid, but the signing key was already expired at the time the artifact was published, which is why GPG reports a good signature from an expired key. In this situation, there is no “updated version” of the same key available on keyservers. Important points to clarify:
What needs to happen to fix this properly:
What cannot be fixed:
So the correct resolution is indeed for the project maintainer to publish a new signing key and use it for future releases. Until then, consumers must either accept the expired key (if policy allows) or treat the artifact as unverifiable. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
07EE2908793B6EAD3EC35AAFB453979C79892013 was used to sign
com/graphql-java/graphql-java/25.0/graphql-java-25.0.jarbut the published key expired by then:and none of
has updated version of said key.
Could the updated key be sent to some keyservers, please?
Beta Was this translation helpful? Give feedback.
All reactions