singa-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Moaz Reyad (JIRA)" <j...@apache.org>
Subject [jira] [Created] (SINGA-456) Adding more PGP Keys
Date Mon, 13 May 2019 13:32:00 GMT
Moaz Reyad created SINGA-456:
--------------------------------

             Summary: Adding more PGP Keys
                 Key: SINGA-456
                 URL: https://issues.apache.org/jira/browse/SINGA-456
             Project: Singa
          Issue Type: Improvement
            Reporter: Moaz Reyad
         Attachments: KEYS

Currently the SINGA [KEYS |https://www.apache.org/dist/incubator/singa/KEYS] file has only
one PGP key which is expiring this September (it needs to be updated). This means only one
person can sign the releases. While other projects like CouchDB for example, have several
keys in the [KEYS |https://www.apache.org/dist/couchdb/KEYS] file.

It will be useful if every active Apache committer in the team create a PGP key and uploads
the Public Key Primary Fingerprint to his account using [Apache Account Utility|https://id.apache.org/].
Then append the new key to the SINGA KEYS file.

Furthermore, the keys themselves can be signed for more trust. SINGA team can exchange key
signatures between them or organize a [key signing party|https://www.apache.org/dev/release-signing#key-signing-party].
This will help adding more SINGA committers into the [Apache Web of Trust|https://www.apache.org/dev/release-signing#web-of-trust].


I attach with this issue the KEYS file with my key appended at the end. 



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Mime
View raw message