Skip to content

GPG public key used to sign release artifacts #747

Description

@HorlogeSkynet

Code of Conduct

  • I have read and agree to the Code of Conduct.
  • Vote on this issue by adding a 👍 reaction to the original issue description to help the maintainers prioritize.
  • Do not leave "+1" or other comments that do not add relevant information or questions.
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment.

Detail

Dear maintainers,

Since transfer of ownership from Hashicorp -> Broadcom and the release of v2.1.0+, the GPG key used to sign artifacts has changed. We couldn't find a way to retrieve the new one across project documentation.

Would it be possible to publish somewhere the public key (or at least its fingerprint) to allow proper* assets signature verification ?

Thanks for your time and your work,
Bye 👋

Suggestion

No response

Activity

  1. self-assigned this
    on Jul 2, 2026
  2. tenthirtyam commented on Jul 2, 2026

    @tenthirtyam
    Collaborator

    I'll review this next week to consider publishing this within the documentation now published directly from the repository.

  3. tenthirtyam commented on Jul 2, 2026

    @tenthirtyam
    Collaborator

    Updated to OP description for context clarity:

    "Since transfer of ownership from Hashicorp -> Broadcom and the release of v2.1.0+, the GPG key used to sign artifacts has changed."

  4. added this to the v2.3.0 milestone on Jul 2, 2026
  5. tenthirtyam commented on Jul 8, 2026

    @tenthirtyam
    Collaborator

    Whilst we wait to publish this in the documentation, users can obtain the public key used to sign releases v2.1.0 and later (post-transfer from HashiCorp to Broadcom) at https://keys.openpgp.org under oss-packer-plugins.pdl@broadcom.com.

    Ryan Johnson, Broadcom

  6. github-actions commented on Aug 3, 2026

    @github-actions

    This functionality has been released in v2.3.0 of the plugin.

    For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template. Thank you!

  7. github-actions commented on Sep 3, 2026

    @github-actions

    I'm going to lock this issue because it has been closed for 30 days. This helps our maintainers find and focus on the active issues.

    If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

  8. locked as resolved and limited conversation to collaborators on Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions