You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@subversion.apache.org by Daniel Shahaf <d....@daniel.shahaf.name> on 2021/02/17 18:57:24 UTC

Fwd: [Mark Thomas: Re: Path and name of KEYS file]

Forwarding with permission.  Quoted matter not covered by permission has
been omitted or paraphrased.

----- Forwarded message from Mark Thomas <ma...@apache.org> -----

> Date: Wed, 17 Feb 2021 17:39:23 +0000
> From: Mark Thomas <markt@>
> To: operations@
> Subject: Re: Path and name of KEYS file
> Reply-To: operations@apache.org
> Message-ID: <81...@apache.org>
> 
> [A quoted person] wrote:
> > [Who owns questions about the policy for pathnames of keyring files
> > in dist/?]
> 
> Since this stems from the release policy, I'd guess the Legal Affairs
> committee.
> 
> > [Each PMC should have a single keyring file, named "KEYS" and placed
> > at the root of its dist/ tree.]
> 
> I think that should be a strong recommendation (SHOULD) rather than a
> hard requirement (MUST).
> 
> The hard requirements are that the KEYS file is:
> - linked from the download page
> - contains the key(s) that signed the release(s) on the download page
> - available to the mirror network
> 
> If the project has a reason to locate the file elsewhere they should be
> free to do so.
> 
> Mark
> 

----- End forwarded message -----