Details
-
Improvement
-
Status: Open
-
Major
-
Resolution: Unresolved
-
None
-
None
-
None
Description
The script at check_staged_release.sh should be improved so that it validates that the public key used for signing a release is part of https://downloads.apache.org/sling/KEYS.
It happened several times in the past that the key was not added there and checking this manually is very error-prone.