Security and Code Signing

Joe Hegarty edited this page Aug 9, 2016 · 11 revisions

Overview

We take security seriously. This page includes information on how to contact us in the event you find a security concern with Orbit. It also lists the public keys you can use to verify a release of Orbit is really from us.

Code Signing

Every release of Orbit is signed according to the standard Maven Central procedures using the keys listed on this page.

Reporting Security Problems

If you wish to report a security issue and do not wish to use GitHub Issues due to the nature of the issue, you can do so by emailing us at orbit-opensource[at]ea.com or using one of the methods listed below. The Orbit public key is listed below should you wish to encrypt your message.

Our Keys

Fingerprint

A88E F8DE C897 B697 6EE2 B3FD D5AA 9A9C 769C 328A

Public Key
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1

mQINBFenv6QBEAC7bCcgDn5x8TE5sz/FaveNiYAlYxCmIcrsrwADucnDKboIJHfp
yfYnZEASANQCdUHNO+HJVPN4SeZ/LlfgsGRKL9ONgO2Ff9zmDX0J9vOPSz5OdG0r
ViQRPNm4oHqJQ518mtTj77E7QQtG3G6drje4IlU4fjH13NinRG4+S1quIaXqSDfQ
f7qjKiQve206v3dlIVLeYYeteHo80JcIVsxmFwY5Q/KNPRU3sEpWXcOCTQz0BViO
Qnn5qVE4UTl9eooJFXqBGUNd3Qalv3Sy0eads2d89cVtAOPJ+RA7Jc86vfyZGTwl
BZDrQV9IglhXKoCCGCHirvl3Pnfv7Zrc47vsFKabaPoYPtKUryQ03h1v5b/R2I+X
j+F6JKjCtDxqCZrwkDW/tY24dZbZqnsKW+3XQJ5HDfIQmYxwuAr6y8FG/vARfviZ
0WmeUPEosN7hMCpAr6up4Sa9mcpMTrawYNSQuc4Bdhycl9oRh3gNIYoOYvzwTGYh
n+/QE0+fiE9Ek8ix2HLEx1S8oZ7Wvrr3k67G6/5V7Qisbyty8ox7NtBE0T1C4SQ1
3IcOukoAuQSiOjiidORwYW9p7yc3a/aA++GPYUK+QNlU5M4nYhwO1a6gLhtBDDO7
KPCQVb5P/8FPKgqz4no/kU/RP5++jLnS02CwYtvoiUrAGqS7m6eVQFJr8wARAQAB
tDBPcmJpdCBEZXZlbG9wbWVudCBUZWFtIDxvcmJpdC1vcGVuc291cmNlQGVhLmNv
bT6JAjgEEwECACIFAlenv6QCGwMGCwkIBwMCBhUIAgkKCwQWAgMBAh4BAheAAAoJ
ENWqmpx2nDKK12QP/Rjdn5cu20FY10p4fXKNYUzU7NcN0LgylJl2SMwjsOliAKJH
MwSHOcjT4GP0E53gpxMHa7YgU/CaGzUFgUqi5xhIo+MTIn6eE2IUsmnYj1dHxBuV
Lz2OZv9lfb1BTeIzMhw5u35TlpF0MhgKbGD5GWOeDHV1Rp927ldn+FmFbkr3CTEC
idEmhNlSQqG6v7jU5kaD6qvlo1a2DqHDZ1AQLeaWTX+lM4LgkDFuWC9oXWkxYktc
oE50BtSIJc52RpJCShVbu7+khicdzI67wtrSXJefzRyVFxRla1crrcizPzy3Qxs2
zC7yC6hHqsc3jELief95vgTJoXYfowkHqxnqBtevHMGNZvyQJ5ihu1hAUtIf8WGS
9kcbRvKI/lj0n13Sk6LDgzsINCjOyx2otk2HYHsSj1wqC7aNsFq69kLmR8271R1t
TuEEHEB5iTRXQrRepH+C2RU3kTjPD82U5MXJDM33MfuDH27NWcBkAvDMAaDI5aGd
hSpbQXuYjjCFKXLp4kiCOJHSuuF4/FviS/iXd65TjG27039QsjyDYdFkP4ajd5G6
X4g1avzHjh+hz8x2v6dD+rjM8+hE+TQZnGdLdlkHzf5m0jo98qxUf8SY3OWHvb3I
dl8I1nzBXpyyenPmw/zwvK5ieCVsclKcGs0K7mclL7X9s7H25xYqi0fzDqbYuQIN
BFenv6QBEAC7ZFJgra0weDrbI0FjyjF1Amkqi17Orc4epdfnJe7xmYWIBJgSe5J2
TqtHjGYxzwBUQTpceHNcUt232raJrDPULxB9Yt1QYEr1VHbzLJ/nuDczoDV2DPa5
ApT4tnCqb0hNaFDUZSB2HhMBtz06S4XDble+9rXB4d/ZnvT3VnQ2RkC3vqti0xVI
RC0b+DLhmXwjIcn+DVudh7XCIIkAlUXk5n7r8cmYKwOIciOYwEw6T+RbjvWdIv5B
mVa9jhdD53Xj+1v8u0gMnEGlrV2UujVhgjktmudvoGniv5nnridYgRYOstKQWy+Y
LcPVHajnLJzQHN5w+mdBxkR4tGKDPXH5gc628r28EIxCH1FyfB9X3Ug/gjHLfCGZ
UMYepbpGwpyOeweocg79lZdrUJQ9cGN1PcImVBQSMm4+R0yCjb2cU8rz5ekVqFWz
UiO0BuaQeTqivnWTfk+nvbfsWIfdISjzCndlHrqoDd+CjWBUsLS3Vq0UHu80zvFl
J+ohuct8REoU7om3usaxysq/GQ79lFvjVD+2okNoHA9mWEuA3zhSZwCONDVVPNf4
amfl/Sn3kOmGSUnJvt2emnZk5Rgpu9xUBfQ8KjfgeORWdIAVZCl5dMyq9cHRS69B
TN0s5IIOCqtge1ZiD+WHVzKskhbKMxsVRrM6c7YTnY0D6o3nH3dftQARAQABiQIf
BBgBAgAJBQJXp7+kAhsMAAoJENWqmpx2nDKK6C0P/iTy85Xt6IgFLshUdTMTjJ8X
1Vfcqg7MF7h6WDyA5FXDT4eLAszyW/l2HPJS2ko9YXHtV8RJgFT2BTzZSuLdSpMu
5I4RaG5Bydh0RmZ3SGpUStSr24GNLLqYz2ZebgvCaetWI+fh2Ttx5cBFQsjvAH3p
xoU8eHemlAguujvgmwvMRqEircfWHpNA1iOAPt4rkKGg37Kwj+i9dfAEDzUnYXZr
FUGnGMyFZHZug75lL9GVintm+Z4iWxrY+1FwYCLpzuiZgDMmHL8X+oUs9hWU+w4X
q99vdAmBLqeso1CQSHEA18p1k4LW9UvVJsp+PvSJkl/M2fMi6gp4Pu5pnVxHaenw
Wxjvae+KHGzEbgk/dLKwLZvh4YsBE/FWOTnYvTGbMpB7sdfSbD2+k3+scb6ZhHgR
wdhkaclEQOJ0owYqKHV5lN+kCmiuz6fj0LfNyiLQvwSyPsb88VKmCl5zsCBwuAV3
atfFDuyxMksTp+eL9UBy4BgfsVDeJY/GgvCweqn5NrHk3AMmfuKSdTVuxGapoT+C
a6s9PVVFkHk2Aob/UnOt+qf+bHTJ/ICI182Y8zIOTOmkKrqHaJ3TRwHGs9deXJJH
Jz/qA9DRs1h9sRNPD+C9XlyxyWenZOre9vt5APZXmp/PVKjXc0NzK3hLcXOhO+xr
oXOy9cHMrSOT0QeVQ1l5
=xeGR
-----END PGP PUBLIC KEY BLOCK-----

Find Us