|
|
|
|
|
by teacup50
4141 days ago
|
|
Maven artifacts can be GPG signed; GPG signing is required for Maven central. It would be irresponsible to use a service like this to build binary JARs that you then signed and uploaded with your own signature guaranteeing their providence. |
|
How many people do you know that verify PGP signatures of their artifacts? Do you?