Hi all, quick question about the Maven Central rel...
# help
d
Hi all, quick question about the Maven Central release signing key. We verify dependency signatures with Gradle. Since 3.5.4, org.wiremock:wiremock has been signed by "WireMock Release Bot release-bot@wiremock.org", fingerprint 0A4A A2D7 C605 3AB0 68D2 06AA 4692 A312 EF60 0C15. The key points to the wiremock/community docs, but I couldn't find the fingerprint there. Can someone confirm this is the official release key? Could it also be published somewhere official? Thanks!
t
Hi Daniel, I believe this is the official key, but will confirm. Good shout about publishing it somewhere official, we’ll do that.
Confirm this is correct
d
Great, thanks!
t
Ah, I’d forgotten - we do publish the key here if this is any help: keys.openpgp.org/search?q=release-bot%40wiremo…