s4u / sign-maven-plugin

Maven plugin which creates Open PGP / GPG signatures for all of the project's artifacts
https://www.simplify4u.org/sign-maven-plugin/
Apache License 2.0
47 stars 7 forks source link

[TODO] Review secret key expiration check #25

Open mkarg opened 3 years ago

mkarg commented 3 years ago

There are questions open wrt to how we currently perform the expiration check for the secret key, see https://github.com/bcgit/bc-java/issues/861. Once this issue is resolved, we possibly need to revise our existing solution.

mkarg commented 3 years ago

In case we actually did the check unsafe, this would be a bug, so I marked this issue as bug pro-forma, as we do not have label for either "todo" or "possible bug".

slawekjaranowski commented 3 years ago

you can add more labels here https://github.com/s4u/.github/blob/master/.github/labels.yml and assign new labels to release category https://github.com/s4u/.github/blob/master/common-files/.github/release-drafter.yml