@@ -57,15 +57,16 @@ to verify that the file has not been tampered with.
57
57
58
58
To verify a SHASUM256.txt.asc, you will first need to import all of
59
59
the GPG keys of individuals authorized to create releases. They are
60
- listed at the bottom of this README. Use a command such as this to
61
- import the keys:
60
+ listed at the bottom of this README under [ Release Team ] ( #release-team ) .
61
+ Use a command such as this to import the keys:
62
62
63
63
```
64
64
$ gpg --keyserver pool.sks-keyservers.net \
65
65
--recv-keys DD8F2338BAE7501E3DD5AC78C273792F7D83545D
66
66
```
67
67
68
- _ (Include each of the key fingerprints at the end of this command.)_
68
+ _ (See the bottom of this README for a full script to import active
69
+ release keys)_
69
70
70
71
You can then use ` gpg --verify SHASUMS256.txt.asc ` to verify that the
71
72
file has been signed by an authorized member of the io.js team.
@@ -336,21 +337,16 @@ that forms the _Technical Steering Committee_ (TSC) which governs the project. F
336
337
information about the governance of the io.js project, see
337
338
[ GOVERNANCE.md] ( ./GOVERNANCE.md ) .
338
339
339
- =======
340
340
### TSC (Technical Steering Committee)
341
341
342
342
* ** Ben Noordhuis
** < ; [email protected] > ; (
[ @bnoordhuis ] ( https://github.com/bnoordhuis ) )
343
343
* ** Bert Belder
** < ; [email protected] > ; (
[ @piscisaureus ] ( https://github.com/piscisaureus ) )
344
344
* ** Fedor Indutny
** < ; [email protected] > ; (
[ @indutny ] ( https://github.com/indutny ) )
345
345
* ** Trevor Norris
** < ; [email protected] > ; (
[ @trevnorris ] ( https://github.com/trevnorris ) )
346
346
* ** Chris Dickinson
** < ; [email protected] > ; (
[ @chrisdickinson ] ( https://github.com/chrisdickinson ) )
347
- - Release GPG key: 9554F04D7259F04124DE6B476D5A82AC7E37093B
348
347
* ** Rod Vagg
** < ; [email protected] > ; (
[ @rvagg ] ( https://github.com/rvagg ) )
349
- - Release GPG key: DD8F2338BAE7501E3DD5AC78C273792F7D83545D
350
348
* ** Jeremiah Senkpiel
** < ; [email protected] > ; (
[ @fishrock123 ] ( https://github.com/fishrock123 ) )
351
- - Release GPG key: FD3A5288F042B6850C66B31F09FE44734EB7990E
352
349
* ** Colin Ihrig
** < ; [email protected] > ; (
[ @cjihrig ] ( https://github.com/cjihrig ) )
353
- - Release GPG key: 94AE36675C464D64BAFA68DD7434390BDBE9B9C5
354
350
* ** Alexis Campailla
** < ; [email protected] > ; (
[ @orangemocha ] ( https://github.com/orangemocha ) )
355
351
* ** Julien Gilli
** < ; [email protected] > ; (
[ @misterdjules ] ( https://github.com/misterdjules ) )
356
352
* ** James M Snell
** < ; [email protected] > ; (
[ @jasnell ] ( https://github.com/jasnell ) )
@@ -393,3 +389,32 @@ information about the governance of the io.js project, see
393
389
394
390
Collaborators & TSC members follow the [ COLLABORATOR_GUIDE.md] ( ./COLLABORATOR_GUIDE.md ) in
395
391
maintaining the io.js project.
392
+
393
+ ### Release Team
394
+
395
+ Releases of Node.js and io.js will be signed with one of the following GPG keys:
396
+
397
+ * ** Chris Dickinson
** < ; [email protected] > ; :
` 9554F04D7259F04124DE6B476D5A82AC7E37093B `
398
+ * ** Colin Ihrig
** < ; [email protected] > ; ` 94AE36675C464D64BAFA68DD7434390BDBE9B9C5 `
399
+ * ** Jeremiah Senkpiel
** < ; [email protected] > ; ` FD3A5288F042B6850C66B31F09FE44734EB7990E `
400
+ * ** Rod Vagg
** < ; [email protected] > ; ` DD8F2338BAE7501E3DD5AC78C273792F7D83545D `
401
+
402
+ The full set of trusted release keys can be imported by running:
403
+
404
+ ```
405
+ gpg --keyserver pool.sks-keyservers.net --recv-keys 9554F04D7259F04124DE6B476D5A82AC7E37093B
406
+ gpg --keyserver pool.sks-keyservers.net --recv-keys 94AE36675C464D64BAFA68DD7434390BDBE9B9C5
407
+ gpg --keyserver pool.sks-keyservers.net --recv-keys FD3A5288F042B6850C66B31F09FE44734EB7990E
408
+ gpg --keyserver pool.sks-keyservers.net --recv-keys DD8F2338BAE7501E3DD5AC78C273792F7D83545D
409
+ ```
410
+
411
+ See the section above on [ Verifying Binaries] ( #verifying-binaries ) for
412
+ details on what to do with these keys to verify a downloaded file is official.
413
+
414
+ Previous releases of Node.js have been signed with one of the following GPG
415
+ keys:
416
+
417
+ * Julien Gilli
< ; [email protected] > ; ` 114F43EE0176B71C7BC219DD50A3051F888C628D `
418
+ * Timothy J Fontaine
< ; [email protected] > ; ` 7937DFD2AB06298B2293C3187D33FF9D0246406D `
419
+ * Isaac Z. Schlueter
< ; [email protected] > ; ` 93C7E9E91B49E432C2F75674B0A78B0A6C481CF6 `
420
+ >>>>>>> b6a4c05... doc: reorg release team to separate section
0 commit comments