mirror of
https://github.com/hashicorp/terraform.git
synced 2026-02-03 20:50:59 -05:00
When verifying the signature of the SHA256SUMS file, we have been hardcoding HashiCorp's public GPG key and using it as the keyring. Going forward, Terraform will get a list of valid public keys for a provider from the Terraform Registry (registry.terraform.io), and use them as the keyring for the openpgp verification func. |
||
|---|---|---|
| .. | ||
| hashicorp.asc | ||
| terraform-provider-badsig_0.1.0_SHA256SUMS | ||
| terraform-provider-badsig_0.1.0_SHA256SUMS.sig | ||
| terraform-provider-template_0.1.0_SHA256SUMS | ||
| terraform-provider-template_0.1.0_SHA256SUMS.sig | ||