From 76080d12cce4ed398925b5acbb21ec7d43735d1f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 25 Jan 2022 01:06:03 +0000 Subject: [PATCH 1/2] Bump svnkit from 1.10.3 to 1.10.4 in /pgp-keys-map-test1 Bumps svnkit from 1.10.3 to 1.10.4. --- updated-dependencies: - dependency-name: org.tmatesoft.svnkit:svnkit dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- pgp-keys-map-test1/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pgp-keys-map-test1/pom.xml b/pgp-keys-map-test1/pom.xml index 29f1b8db4..20328dfc2 100644 --- a/pgp-keys-map-test1/pom.xml +++ b/pgp-keys-map-test1/pom.xml @@ -881,7 +881,7 @@ org.tmatesoft.svnkit svnkit - [1.10.3] + [1.10.4] org.bouncycastle From e346c4c07738184b21b56a96bd2550e789028c97 Mon Sep 17 00:00:00 2001 From: "AO Industries, Inc" Date: Fri, 4 Feb 2022 13:45:26 -0600 Subject: [PATCH 2/2] Additional key for org.tmatesoft.* Key exists in keys.openpgp.org but contains no user ID. This basically means this commit blindly accepts this signing key without any meaningful identity verification. I was unable to find any relevant GitHub for the project, only older versions and forks. I do not find any signing key information on the download page at https://svnkit.com/download.php I do not find any signing key information at the SVN tag at https://svn.svnkit.com/repos/svnkit/tags/1.10.4/ --- resources/pgp-keys-map.list | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/resources/pgp-keys-map.list b/resources/pgp-keys-map.list index eaf5eb911..de6a6b8dd 100644 --- a/resources/pgp-keys-map.list +++ b/resources/pgp-keys-map.list @@ -1028,7 +1028,9 @@ org.tmatesoft:svnkit = noSig org.tmatesoft.svnkit:svnkit:(,1.3.5] = noSig org.tmatesoft.svnkit:svnkit-javahl = noSig org.tmatesoft.svnkit:trilead-ssh2 = noSig -org.tmatesoft.* = 0x4D90040F09023A4A74DF2F54ABAAE54F37E6F8E1 +org.tmatesoft.* = \ + 0x36DFABCC7D7F357C9E04536D06294B7D913FB160, \ + 0x4D90040F09023A4A74DF2F54ABAAE54F37E6F8E1 org.tukaani = 0x3690C240CE51B4670D30AD1C38EE757D69184620