@@ -57,15 +57,16 @@ to verify that the file has not been tampered with.
57
57
58
58
To verify a SHASUM256.txt.asc, you will first need to import all of
59
59
the GPG keys of individuals authorized to create releases. They are
60
- listed at the bottom of this README. Use a command such as this to
61
- import the keys:
60
+ listed at the bottom of this README under [ Release Team ] ( #release-team ) .
61
+ Use a command such as this to import the keys:
62
62
63
63
```
64
64
$ gpg --keyserver pool.sks-keyservers.net \
65
65
--recv-keys DD8F2338BAE7501E3DD5AC78C273792F7D83545D
66
66
```
67
67
68
- _ (Include each of the key fingerprints at the end of this command.)_
68
+ _ (See the bottom of this README for a full script to import active
69
+ release keys)_
69
70
70
71
You can then use ` gpg --verify SHASUMS256.txt.asc ` to verify that the
71
72
file has been signed by an authorized member of the io.js team.
@@ -336,21 +337,16 @@ that forms the _Technical Steering Committee_ (TSC) which governs the project. F
336
337
information about the governance of the io.js project, see
337
338
[ GOVERNANCE.md] ( ./GOVERNANCE.md ) .
338
339
339
- =======
340
340
### TSC (Technical Steering Committee)
341
341
342
342
* ** Ben Noordhuis** < ; info@bnoordhuis.nl > ; ([ @bnoordhuis ] ( https://github.com/bnoordhuis ) )
343
343
* ** Bert Belder** < ; bertbelder@gmail.com > ; ([ @piscisaureus ] ( https://github.com/piscisaureus ) )
344
344
* ** Fedor Indutny** < ; fedor.indutny@gmail.com > ; ([ @indutny ] ( https://github.com/indutny ) )
345
345
* ** Trevor Norris** < ; trev.norris@gmail.com > ; ([ @trevnorris ] ( https://github.com/trevnorris ) )
346
346
* ** Chris Dickinson** < ; christopher.s.dickinson@gmail.com > ; ([ @chrisdickinson ] ( https://github.com/chrisdickinson ) )
347
- - Release GPG key: 9554F04D7259F04124DE6B476D5A82AC7E37093B
348
347
* ** Rod Vagg** < ; rod@vagg.org > ; ([ @rvagg ] ( https://github.com/rvagg ) )
349
- - Release GPG key: DD8F2338BAE7501E3DD5AC78C273792F7D83545D
350
348
* ** Jeremiah Senkpiel** < ; fishrock123@rocketmail.com > ; ([ @fishrock123 ] ( https://github.com/fishrock123 ) )
351
- - Release GPG key: FD3A5288F042B6850C66B31F09FE44734EB7990E
352
349
* ** Colin Ihrig** < ; cjihrig@gmail.com > ; ([ @cjihrig ] ( https://github.com/cjihrig ) )
353
- - Release GPG key: 94AE36675C464D64BAFA68DD7434390BDBE9B9C5
354
350
* ** Alexis Campailla** < ; orangemocha@nodejs.org > ; ([ @orangemocha ] ( https://github.com/orangemocha ) )
355
351
* ** Julien Gilli** < ; jgilli@nodejs.org > ; ([ @misterdjules ] ( https://github.com/misterdjules ) )
356
352
* ** James M Snell** < ; jasnell@gmail.com > ; ([ @jasnell ] ( https://github.com/jasnell ) )
@@ -393,3 +389,32 @@ information about the governance of the io.js project, see
393
389
394
390
Collaborators & TSC members follow the [ COLLABORATOR_GUIDE.md] ( ./COLLABORATOR_GUIDE.md ) in
395
391
maintaining the io.js project.
392
+
393
+ ### Release Team
394
+
395
+ Releases of Node.js and io.js will be signed with one of the following GPG keys:
396
+
397
+ * ** Chris Dickinson** < ; christopher.s.dickinson@gmail.com > ; : ` 9554F04D7259F04124DE6B476D5A82AC7E37093B `
398
+ * ** Colin Ihrig** < ; cjihrig@gmail.com > ; ` 94AE36675C464D64BAFA68DD7434390BDBE9B9C5 `
399
+ * ** Jeremiah Senkpiel** < ; fishrock@keybase.io > ; ` FD3A5288F042B6850C66B31F09FE44734EB7990E `
400
+ * ** Rod Vagg** < ; rod@vagg.org > ; ` DD8F2338BAE7501E3DD5AC78C273792F7D83545D `
401
+
402
+ The full set of trusted release keys can be imported by running:
403
+
404
+ ```
405
+ gpg --keyserver pool.sks-keyservers.net --recv-keys 9554F04D7259F04124DE6B476D5A82AC7E37093B
406
+ gpg --keyserver pool.sks-keyservers.net --recv-keys 94AE36675C464D64BAFA68DD7434390BDBE9B9C5
407
+ gpg --keyserver pool.sks-keyservers.net --recv-keys FD3A5288F042B6850C66B31F09FE44734EB7990E
408
+ gpg --keyserver pool.sks-keyservers.net --recv-keys DD8F2338BAE7501E3DD5AC78C273792F7D83545D
409
+ ```
410
+
411
+ See the section above on [ Verifying Binaries] ( #verifying-binaries ) for
412
+ details on what to do with these keys to verify a downloaded file is official.
413
+
414
+ Previous releases of Node.js have been signed with one of the following GPG
415
+ keys:
416
+
417
+ * Julien Gilli < ; jgilli@fastmail.fm > ; ` 114F43EE0176B71C7BC219DD50A3051F888C628D `
418
+ * Timothy J Fontaine < ; tjfontaine@gmail.com > ; ` 7937DFD2AB06298B2293C3187D33FF9D0246406D `
419
+ * Isaac Z. Schlueter < ; i@izs.me > ; ` 93C7E9E91B49E432C2F75674B0A78B0A6C481CF6 `
420
+ >>>>>>> b6a4c05... doc: reorg release team to separate section
0 commit comments