The project that I work on has some defences in place against supply chain attack, this requires that any code we either deploy or use during our product release process has to be signed by a verifiable signature. See here for the details
I am currently refreshing our dependencies and I see that version 3.1 is signed with GPG key 0x340B090F727518D8
It is extremely helpful to developers everywhere that software can be verified as coming from you. In our case we cannot move forward important dependencies without it. I would therefore be grateful if you could upload all your public keys to your git repository (or any of the other places noted in the link above).
Thank you
Rod
The project that I work on has some defences in place against supply chain attack, this requires that any code we either deploy or use during our product release process has to be signed by a verifiable signature. See here for the details
I am currently refreshing our dependencies and I see that version 3.1 is signed with GPG key 0x340B090F727518D8
It is extremely helpful to developers everywhere that software can be verified as coming from you. In our case we cannot move forward important dependencies without it. I would therefore be grateful if you could upload all your public keys to your git repository (or any of the other places noted in the link above).
Thank you
Rod