Skip to content

Missing chain of trust for 1.3.6 pypi sdist tarball

Hi! Similar to mailman#948 the sdist tarball for postorius 1.3.6 has also been signed with the wrong PGP key (891C60724B58650CB1C4A6030D35F23FF689B708).

I will also switch to using a git clone of this repository to be able to verify the tags using the known key:

git verify-tag 1.3.6
gpg: Signature made 2021-09-29T04:53:48 CEST
gpg:                using RSA key 541EA0448453394FF77A0ECC9D9B2BA061D0A67C
gpg:                issuer "raj.abhilash1@gmail.com"
gpg: Good signature from "Abhilash Raj <raj.abhilash1@gmail.com>" [unknown]
gpg:                 aka "Abhilash Raj <maxking@asynchronous.in>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: 541E A044 8453 394F F77A  0ECC 9D9B 2BA0 61D0 A67C

Anyways, it would be great if you could provide a signature for 891C60724B58650CB1C4A6030D35F23FF689B708 using 541EA0448453394FF77A0ECC9D9B2BA061D0A67C.