The Linux Foundation's "sigstore" project
The Linux Foundation's "sigstore" project
Posted Mar 11, 2021 7:51 UTC (Thu) by LtWorf (subscriber, #124958)In reply to: The Linux Foundation's "sigstore" project by shemminger
Parent article: The Linux Foundation's "sigstore" project
I think this is more for clueless projects like yarn that when the repository key expires just make a new one.
No thought about making a keyring package and use it to introduce the new key before the old one expires.
