-
Type:
Task
-
Resolution: Unresolved
-
Priority:
Unknown
-
None
-
Affects Version/s: None
-
Component/s: None
-
None
-
Needed
-
None
-
C Drivers
-
None
-
None
-
None
-
None
-
None
-
None
The release.py script currently signs using the current developer's git identity and signing key. We may want to switch to using the dedicated Release Signing Key used to create a signature file for the release tarball instead. This would improve the user experience for those validating the release tag signature, as they can (re)use the dedicated Release Signing Key provided by https://pgp.mongodb.com/, rather than needing to find and import individual developers' public keys.
- causes
-
PHPC-2575 Investigate changes in CDRIVER-5994: Sign Release Tags with the C Driver Release Signing Key
-
- Closed
-
- is related to
-
CDRIVER-5529 Policy: DBX Repository and Commit Security
-
- Closed
-