forked from ChelseaKR/qfer-preflight
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathallowed_signers
More file actions
13 lines (13 loc) · 762 Bytes
/
Copy pathallowed_signers
File metadata and controls
13 lines (13 loc) · 762 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
# SSH allowed signers, consumed by `git verify-tag` in the release workflow.
#
# One line per signing identity, in the format git's gpg.ssh.allowedSignersFile
# expects:
# <principal> namespaces="git" <key-type> <public-key>
#
# Public keys only. Nothing secret belongs in this file.
# The principal below is the maintainer's release-signing key, checked against
# the GitHub API (users/ChelseaKR/ssh_signing_keys) on 2026-08-17, where it is
# recorded as "outcome-receipts release signing". A tag signed by any other key
# does not verify, and the release workflow fails closed if this file ever
# lists no principal.
3114598+ChelseaKR@users.noreply.github.com namespaces="git" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIOjn/aI0d9jElCoi7qT4+6j9UmgTH7vLGAqJXiKMoCE