Skip to content

Update for new GPG keys - #1471

Draft
jrfnl wants to merge 1 commit into
3.xfrom
feature/update-gpg-key-info
Draft

Update for new GPG keys#1471
jrfnl wants to merge 1 commit into
3.xfrom
feature/update-gpg-key-info

Conversation

@jrfnl

@jrfnl jrfnl commented Aug 1, 2026

Copy link
Copy Markdown
Member

Description

The GPG key used to expire every year - as per the recommendation, so a new key has been generated and uploaded to the openpgp database.
However, as we now also use attestations for the generated PHAR files, the expiry period for the new GPG key has been set to five years.

Suggested changelog entry

  • The GPG signature for the PHAR files has been rotated. The new fingerprint is: 5CB4F778BF9BC4FB67AE511D96E91A992CF22FF4.

Notes

  • This PR should be rebased once new releases using the new key have been created.
  • The PR should only be merged after that as otherwise the "Verify release" workflow will fail (as it would try to check older releases against the new key)
  • The changelog entry should be included in the changelog for the 3.13.6/4.0.2 releases though.

The GPG key used to expire every year - as per the recommendation, so a new key has been generated and uploaded to the openpgp database.
However, as we now _also_ use attestations for the generated PHAR files, the expiry period for the new GPG key has been set to five years.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant