phpmd / phpmd

PHPMD is a spin-off project of PHP Depend and aims to be a PHP equivalent of the well known Java tool PMD. PHPMD can be seen as an user friendly frontend application for the raw metrics stream measured by PHP Depend.

Home Page:https://phpmd.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Finish signing phar file

tvbeek opened this issue · comments

  • PHPMD version: 2.13.0
  • PHP Version: -
  • Installation type: phive
  • Operating System / Distribution & Version: All

The phar file isn't signed yet because of the missing secrets:

PASSPHRASE: 
SECRET_KEY: 

@ravage84 thanks for signing. Can you communicate the correct public key somewhere? Otherwise we might just have to accept any key on first contact and that is no better than having unsigned packages (it just means that sombody signed this blob).

Maybe a note in the README and/or the download page that "the phar is signed with this key ..."

It seems the key currently in use is E7A7 4510 2ECC 980F 7338 B307 9093 F8B3 2E48 15AA. Is that correct.

@lucc All the keys available can be found here:

https://keys.openpgp.org/search?q=pgp%40phpmd.org