Skip to content

Complete historical key archive and maintenance closeout - #209

Merged
jmanico merged 1 commit into
mainfrom
docs/historical-keys-final-audit
Sep 27, 2026
Merged

jmanico merged 1 commit into
mainfrom
docs/historical-keys-final-audit

Conversation

@jmanico

@jmanico jmanico commented Sep 27, 2026

Copy link
Copy Markdown
Member

Change

Completes the four remaining historical signing-key records and the maintenance backlog audit. KEYS now contains authenticated archival public keys for 1.1, 1.1.1, 1.2 and 1.2.1; VERIFYING.md uses the published 1.4.1 release in its consumer commands.

Jim Manico explicitly authenticated the first three exact fingerprints in the maintainer session, citing his involvement from the project's beginning and recruitment of Jeff Ichnowski. This is recorded as retrospective maintainer authentication, not a recovered contemporaneous fingerprint announcement or private-key custody claim. The 1.2.1 fingerprint independently matches Jeremy Long's public GitHub account key record 213069; the public packet and API metadata are preserved for reproducibility. Expiry, old algorithms and source limits remain explicit.

The closeout inventories the original 30 batch issues, subsequent dependency PR dispositions, completed #111 publication/custody follow-up, and the final two issues. Development remains 1.5.0-SNAPSHOT; a future 1.5 release still requires the full then-open backlog review and explicit release approval.

Closes #110.
Closes #169.

Compatibility and validation

Documentation and public-key archive only; no artifact inputs, published assets, signatures, tags or repository protections change. All three pre-existing public-key blocks are byte-for-byte unchanged.

  • GnuPG 2.5.20, fresh isolated home: seven primary public keys, zero secret keys; all ten original Central core JAR signatures from 1.1 through 1.4.1 returned VALIDSIG for the expected full fingerprint. Historical expiry warnings retained; no weak-digest, clock or trust override.

  • Both documented consumer shell blocks passed against Central 1.4.1; analogous SHA-512 check passed; a wrong expected fingerprint was rejected.

  • Both original 1.4.1 signed checksum manifests verified, each with 35 passing entries.

  • Archived GitHub public-key packet fingerprint/hash independently recomputed; 38 local documentation links and all ten evidence records checked; git diff --check passed.

  • Required GitHub CI/security checks must pass at this head before merge. No separate local Maven rebuild is claimed for these documentation/public-key-only changes.

  • I kept the change scoped and preserved relevant notices.

  • I checked documentation/changelog and tests for any behavior change.

  • This PR contains no credentials or private vulnerability evidence.

@jmanico
jmanico requested a review from jeremylong as a code owner September 27, 2026 05:16
@jmanico
jmanico merged commit 07d8e58 into main Sep 27, 2026
28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Maintenance execution plan: ordered batches and backlog review (2026-09-25) Complete historical release-key records and verify consumer instructions

1 participant