Verified Commit bc007ca5 authored by David Runge's avatar David Runge 🐿
Add releases section with PGP information

Add a "Releases" section that specifies who is creating releases and which PGP key ID is used to sign tags.
Additionally, information about how to retrieve the relevant public key and how to verify a tag in the repository is

Fixes #114
parent d178183c
Pipeline #6004 passed with stages
in 39 minutes and 3 seconds
......@@ -148,6 +148,26 @@ Discussion around archiso takes place on the `arch-releng mailing list
All past and present authors of archiso are listed in `AUTHORS <AUTHORS.rst>`_.
`Releases of archiso <>`_ are created by its current maintainer
`David Runge <>`_. Tags are signed using the PGP key with the ID
To verify a tag, first import the relevant PGP key:
.. code:: bash
gpg --auto-key-locate wkd --search-keys
Afterwards a tag can be verified from a clone of this repository:
.. code:: bash
git verify-tag <tag>
