Skip to content

Conversation

@raboof
Copy link
Member

@raboof raboof commented Nov 24, 2025

This key was generated by Infra to allow staging releases from CI. This request was tracked as https://issues.apache.org/jira/browse/INFRA-27312

As per the ASF Release Policy, artifacts signed with this key should never be automatically published to user-facing location, but always first published to a staging area, verified (typically by the PMC), and then promoted (typically by the RM). This is already part of our release process

No human should have access to the corresponding private key. If we ever have reason to believe this key was compromised, the PMC has access to a corresponding revocation key.

This key was generated by Infra to allow staging releases from CI.
This request was tracked as https://issues.apache.org/jira/browse/INFRA-27312

As per the [ASF Release Policy](https://www.apache.org/legal/release-policy.html#owned-controlled-hardware),
artifacts signed with this key should never be automatically published
to user-facing location, but always first published to a staging area, verified
(typically by the PMC), and then promoted (typically by the RM). This is
already part of our [release process](https://github.com/apache/pekko-site/wiki/Pekko-Release-Process)

No human should have access to the corresponding private key. If we ever
have reason to believe this key was compromised, the PMC has access to a
corresponding revocation key.
Copy link
Member

@pjfanning pjfanning left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lgtm

@raboof raboof merged commit fd5e8c9 into apache:main Nov 24, 2025
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants