Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

3.0.0: signature key-id 763629FEC8788FC35128B5F6EE029D1E5EB40300 not found #55

Open
dvzrv opened this issue Feb 15, 2020 · 5 comments
Open
Labels

Comments

@dvzrv
Copy link

@dvzrv dvzrv commented Feb 15, 2020

For the same reasons I can not build and package gitpython for Arch Linux, I can not build and package gitdb in version 3.0.0.

Please fix the trust chain for the new key or release a new version with the already trusted key.

@Byron Byron added the acknowledged label Feb 15, 2020
@Byron
Copy link
Member

@Byron Byron commented Feb 15, 2020

Thanks for the reminder - please refer to the linked issue for the anticipated course of action.

@Byron
Copy link
Member

@Byron Byron commented Apr 11, 2020

@dvzrv I have just released v4.0.4 which should be signed with the known key. CC @Harmon758

In May we should be able to move package signing to CI while maintaining a chain of trust.

@dvzrv
Copy link
Author

@dvzrv dvzrv commented Apr 11, 2020

@Byron thanks for being on top of this! :)

I have one follow up question: Why is the package now again pushed to gitdb and not as before gitdb2?

@Byron
Copy link
Member

@Byron Byron commented Apr 11, 2020

Please don't mind the above, I used the wrong signing key.

The way I understand it, gitdb2 is just for use by older GitPython releases, where is gitdb is the package we use from here on. The reason for gitdb2 to come into existence in the first place was me losing access to my pypi account when they disabled support for Google as login mechanism.

It's a great reminder though, as probably I should also re-release gitdb2 with the correct signing key for it to be picked up one last time.

@Byron
Copy link
Member

@Byron Byron commented May 5, 2020

Release 4.0.5 was created and signed with 2CF6E0B51AAF73F09B1C21174D1DA68C88710E60.
Please feel free to close this issue when verified to be correct.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants