Skip to content

Conversation

@StanFromIreland
Copy link
Member

It wasn't quite clear which of the three keys are used, so I tested all three and found the one that was used for the last release. Furthermore, reading this discussion, it seems the future of the signing is not certain.

@eggert can you please confirm that ed97e90e62aa7e34 is used?

@eggert
Copy link

eggert commented Sep 17, 2025

@eggert can you please confirm that ed97e90e62aa7e34 is used?

The key I used can be found on my Savannah profile page.

@StanFromIreland
Copy link
Member Author

Thank you for confirming.

@pganssle
Copy link
Member

Thanks for doing this @StanFromIreland!

For reference for future maintainers (including us, in case we forget 😅): If they stop signing the tzdata releases in the future, or if this turns out to just create a bunch of pointless noise, we can just disable this check. It's a nice-to-have thing as long as the signing works well, but my impression is that the modern view of GPG-signed releases is that it doesn't add much to the security model, and plus I don't see it as especially risky if we get malicious data anyway.

@pganssle pganssle merged commit b5ab93f into python:master Sep 18, 2025
27 checks passed
@StanFromIreland StanFromIreland deleted the verify branch September 18, 2025 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants