j4-dmenu-desktop icon indicating copy to clipboard operation
j4-dmenu-desktop copied to clipboard

Signed releases

Open meator opened this issue 10 months ago • 5 comments

Hi @enkore. I have done some work since you gave me write permissions to this repo. I am considering making a new release. There is still a lot of work to be done but I would like to make a new release when the time comes. I have noticed that https://github.com/enkore/j4-dmenu-desktop/blob/develop/HOW-TO-RELEASE#L5 mentions signing the new release. I don't have a private key for A1774C1B37DC1DCEDB65EE469B8450B91D1362C1 so I can't make signed releases. Would you be willing to sign it? I'd like to make releases too. I see these solutions:

  1. You (@enkore) will sign each release.
  2. New releases won't be signed (I won't sign the next release if you don't respond to this before I make v3.0).
  3. I could sign releases with my key.
  4. We could somehow share the secrets & be both able to make signed releases.

I'm not a GPG expert (but I'm not a GPG beginner either). I don't really know how 4. would work. You could send me the private key and its password but that has obvious disadvantages.

What are your thoughts on this?

meator avatar Sep 12 '23 15:09 meator