Complete historical key archive and maintenance closeout - #209
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
Completes the four remaining historical signing-key records and the maintenance backlog audit.
KEYSnow contains authenticated archival public keys for 1.1, 1.1.1, 1.2 and 1.2.1;VERIFYING.mduses the published 1.4.1 release in its consumer commands.Jim Manico explicitly authenticated the first three exact fingerprints in the maintainer session, citing his involvement from the project's beginning and recruitment of Jeff Ichnowski. This is recorded as retrospective maintainer authentication, not a recovered contemporaneous fingerprint announcement or private-key custody claim. The 1.2.1 fingerprint independently matches Jeremy Long's public GitHub account key record 213069; the public packet and API metadata are preserved for reproducibility. Expiry, old algorithms and source limits remain explicit.
The closeout inventories the original 30 batch issues, subsequent dependency PR dispositions, completed #111 publication/custody follow-up, and the final two issues. Development remains
1.5.0-SNAPSHOT; a future 1.5 release still requires the full then-open backlog review and explicit release approval.Closes #110.
Closes #169.
Compatibility and validation
Documentation and public-key archive only; no artifact inputs, published assets, signatures, tags or repository protections change. All three pre-existing public-key blocks are byte-for-byte unchanged.
GnuPG 2.5.20, fresh isolated home: seven primary public keys, zero secret keys; all ten original Central core JAR signatures from 1.1 through 1.4.1 returned
VALIDSIGfor the expected full fingerprint. Historical expiry warnings retained; no weak-digest, clock or trust override.Both documented consumer shell blocks passed against Central 1.4.1; analogous SHA-512 check passed; a wrong expected fingerprint was rejected.
Both original 1.4.1 signed checksum manifests verified, each with 35 passing entries.
Archived GitHub public-key packet fingerprint/hash independently recomputed; 38 local documentation links and all ten evidence records checked;
git diff --checkpassed.Required GitHub CI/security checks must pass at this head before merge. No separate local Maven rebuild is claimed for these documentation/public-key-only changes.
I kept the change scoped and preserved relevant notices.
I checked documentation/changelog and tests for any behavior change.
This PR contains no credentials or private vulnerability evidence.