3 ms·
Releases have to be PGP signed, snapshot's don't. How many people do you know that verify PGP signatures of their artifacts? Do you?
by jermo 12y ago
Releases have to be PGP signed, snapshot's don't.
How many people do you know that verify PGP signatures of their artifacts? Do you?
- teacup50 12y agoYes, we verify signatures at our middleware repository cache.
- pron 12y agoReally? Impressive! Where do you get the public keys? Most projects hosted on Maven Central don't publish them on their website.
- teacup50 12y agohttp://blog.sonatype.com/2009/04/nexus-133-introduces-automatic-signature-verification-to-maven-artifacts/ http://blog.sonatype.com/2009/04/nexus-133-introduces-automa...
- pron 12y agoBut unless the signers have a public certificate, or publish their public keys on their website (which you need to obtain manually), the signatures on Maven Central can be just as fake as the artifacts.