ppkarwasz opened a new issue, #170:
URL: https://github.com/apache/tooling-trusted-release/issues/170

   Log4j releases are built using GitHub Actions, which results in the 
following ATR error:
   
   > `Verifying key lacks an ASF UID`
   
   This is expected, as GitHub Actions does not use a key tied to an ASF UID — 
it's an automated workflow.
   
   While we may eventually include *in-toto* attestations to capture the 
triggering user's identity, what’s the recommended workaround for this 
scenario? Can ATR support trusted CI keys or allow an override for automated 
builds in the meantime?
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to