Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Signing releases #16556

Closed
aerusso opened this issue Oct 26, 2023 · 3 comments
Closed

Signing releases #16556

aerusso opened this issue Oct 26, 2023 · 3 comments
Labels
X-Needs-Info This issue is blocked awaiting information from the reporter

Comments

@aerusso
Copy link

aerusso commented Oct 26, 2023

Description:

Hello! I apologize if this is somewhere, but I cannot seem to find it if it exists. I would like to cryptographically verify the releases of matrix-synapse. I can see that the release-tagged commits are signed, but I cannot seem to find public information on which key(s) I should trust signatures from. Ideally, there would be a link in the readme to some web page on matrix.org listing a public key, and the tags are signed with that key. Even better if that same pgp key is used to sign everything (packages, release tags, etc.).

Thanks for the great work!

@clokep
Copy link
Member

clokep commented Oct 26, 2023

The debian packages are signed: https://matrix-org.github.io/synapse/latest/setup/installation.html#matrixorg-packages

Can you provide more info about what sort of install you're using?

@clokep clokep added the X-Needs-Info This issue is blocked awaiting information from the reporter label Oct 26, 2023
@DMRobertson
Copy link
Contributor

Is this basically #15994 ?

@aerusso
Copy link
Author

aerusso commented Oct 26, 2023

Oh shoot, yes. Sorry, I did not mean to open a second issue (I actually completely forgot that I already did that). I'll go ahead and close since it's a duplicate.

@aerusso aerusso closed this as completed Oct 26, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
X-Needs-Info This issue is blocked awaiting information from the reporter
Projects
None yet
Development

No branches or pull requests

3 participants