Live data from Hacker News

Just-in-time packager for GitHub repositories

jitpack.io

31–33 of 33 posts

Re: Just-in-time packager for GitHub repositories

#31
post #24

Earlier quoted context omitted.

Releases have to be PGP signed, snapshot's don't. How many people do you know that verify PGP signatures of their artifacts? Do you?

Yes, we verify signatures at our middleware repository cache.

Really? Impressive! Where do you get the public keys? Most projects hosted on Maven Central don't publish them on their website.

Re: Just-in-time packager for GitHub repositories

#32
post #31

Earlier quoted context omitted.

Yes, we verify signatures at our middleware repository cache.

Really? Impressive! Where do you get the public keys? Most projects hosted on Maven Central don't publish them on their website.

http://blog.sonatype.com/2009/04/nexus-133-introduces-automa...

Re: Just-in-time packager for GitHub repositories

#33
post #31

Earlier quoted context omitted.

Really? Impressive! Where do you get the public keys? Most projects hosted on Maven Central don't publish them on their website.

http://blog.sonatype.com/2009/04/nexus-133-introduces-automa...

But unless the signers have a public certificate, or publish their public keys on their website (which you need to obtain manually), the signatures on Maven Central can be just as fake as the artifacts.
Post reply on HN