feat: add trusted Automated Release Signing key #2530
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This key was generated by Infra to allow staging releases from CI. This request was tracked as https://issues.apache.org/jira/browse/INFRA-27312
As per the ASF Release Policy, artifacts signed with this key should never be automatically published to user-facing location, but always first published to a staging area, verified (typically by the PMC), and then promoted (typically by the RM). This is already part of our release process
No human should have access to the corresponding private key. If we ever have reason to believe this key was compromised, the PMC has access to a corresponding revocation key.