{"id":15010506,"url":"https://github.com/nodejs/release-keys","last_synced_at":"2025-10-19T22:30:48.016Z","repository":{"id":37798790,"uuid":"208073785","full_name":"nodejs/release-keys","owner":"nodejs","description":"Node.js release signing keys.","archived":false,"fork":false,"pushed_at":"2024-10-10T15:40:36.000Z","size":348,"stargazers_count":12,"open_issues_count":6,"forks_count":11,"subscribers_count":12,"default_branch":"main","last_synced_at":"2024-10-29T16:13:22.302Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nodejs.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2019-09-12T14:42:14.000Z","updated_at":"2024-10-10T15:40:37.000Z","dependencies_parsed_at":"2024-11-06T17:31:34.076Z","dependency_job_id":"c4164700-ee68-4d21-9d48-f025365c6ca2","html_url":"https://github.com/nodejs/release-keys","commit_stats":{"total_commits":29,"total_committers":11,"mean_commits":"2.6363636363636362","dds":"0.48275862068965514","last_synced_commit":"604322f38d5cc74bc7552af75f1d3b4d6e8825ac"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Frelease-keys","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Frelease-keys/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Frelease-keys/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Frelease-keys/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nodejs","download_url":"https://codeload.github.com/nodejs/release-keys/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":237221171,"owners_count":19274447,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-09-24T19:34:33.320Z","updated_at":"2025-10-19T22:30:48.009Z","avatar_url":"https://github.com/nodejs.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Node.js Release Keys\n\nPrimary GPG keys for Node.js Releasers (some Releasers sign with subkeys):\n\n\u003c!-- Active releasers keys --\u003e\n\n* **Antoine du Hamel** \u003c\u003cduhamelantoine1995@gmail.com\u003e\u003e\n  [`5BE8A3F6C8A5C01D106C0AD820B1A390B168D356`](./keys/5BE8A3F6C8A5C01D106C0AD820B1A390B168D356.asc)\n* **Juan José Arboleda** \u003c\u003csoyjuanarbol@gmail.com\u003e\u003e\n  [`DD792F5973C6DE52C432CBDAC77ABFA00DDBF2B7`](./keys/DD792F5973C6DE52C432CBDAC77ABFA00DDBF2B7.asc)\n* **Marco Ippolito** \u003c\u003cmarcoippolito54@gmail.com\u003e\u003e\n  [`CC68F5A3106FF448322E48ED27F5E38D5B0A215F`](./keys/CC68F5A3106FF448322E48ED27F5E38D5B0A215F.asc)\n* **Michaël Zasso** \u003c\u003ctargos@protonmail.com\u003e\u003e\n  [`8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600`](./keys/8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600.asc)\n* **Rafael Gonzaga** \u003c\u003crafael.nunu@hotmail.com\u003e\u003e\n  [`890C08DB8579162FEE0DF9DB8BEAB4DFCF555EF4`](./keys/890C08DB8579162FEE0DF9DB8BEAB4DFCF555EF4.asc)\n* **Richard Lau** \u003c\u003crichard.lau@ibm.com\u003e\u003e\n  [`C82FA3AE1CBEDC6BE46B9360C43CEC45C17AB93C`](./keys/C82FA3AE1CBEDC6BE46B9360C43CEC45C17AB93C.asc)\n* **Ruy Adorno** \u003c\u003cruyadorno@hotmail.com\u003e\u003e\n  [`108F52B48DB57BB0CC439B2997B01419BD92F80A`](./keys/108F52B48DB57BB0CC439B2997B01419BD92F80A.asc)\n* **Ulises Gascón** \u003c\u003culisesgascongonzalez@gmail.com\u003e\u003e\n  [`A363A499291CBBC940DD62E41F10027AF002F8B0`](./keys/A363A499291CBBC940DD62E41F10027AF002F8B0.asc)\n\n\u003c!-- /Active releasers keys --\u003e\n\nOther keys used to sign some previous releases:\n\n\u003c!-- Retired keys --\u003e\n\n* **Antoine du Hamel** \u003c\u003cduhamelantoine1995@gmail.com\u003e\u003e\n  [`C0D6248439F1D5604AAFFB4021D900FFDB233756`](./keys/C0D6248439F1D5604AAFFB4021D900FFDB233756.asc)\n* **Beth Griggs** \u003c\u003cbethanyngriggs@gmail.com\u003e\u003e\n  [`4ED778F539E3634C779C87C6D7062848A1AB005C`](./keys/4ED778F539E3634C779C87C6D7062848A1AB005C.asc)\n* **Bryan English** \u003c\u003cbryan@bryanenglish.com\u003e\u003e\n  [`141F07595B7B3FFE74309A937405533BE57C7D57`](./keys/141F07595B7B3FFE74309A937405533BE57C7D57.asc)\n* **Chris Dickinson** \u003c\u003cchristopher.s.dickinson@gmail.com\u003e\u003e\n  [`9554F04D7259F04124DE6B476D5A82AC7E37093B`](./keys/9554F04D7259F04124DE6B476D5A82AC7E37093B.asc)\n* **Colin Ihrig** \u003c\u003ccjihrig@gmail.com\u003e\u003e\n  [`94AE36675C464D64BAFA68DD7434390BDBE9B9C5`](./keys/94AE36675C464D64BAFA68DD7434390BDBE9B9C5.asc)\n* **Danielle Adams** \u003c\u003cadamzdanielle@gmail.com\u003e\u003e\n  [`1C050899334244A8AF75E53792EF661D867B9DFA`](./keys/1C050899334244A8AF75E53792EF661D867B9DFA.asc)\n  [`74F12602B6F1C4E913FAA37AD3A89613643B6201`](./keys/74F12602B6F1C4E913FAA37AD3A89613643B6201.asc)\n* **Evan Lucas** \u003c\u003cevanlucas@me.com\u003e\u003e\n  [`B9AE9905FFD7803F25714661B63B535A4C206CA9`](./keys/B9AE9905FFD7803F25714661B63B535A4C206CA9.asc)\n* **Gibson Fahnestock** \u003c\u003cgibfahn@gmail.com\u003e\u003e\n  [`77984A986EBC2AA786BC0F66B01FBB92821C587A`](./keys/77984A986EBC2AA786BC0F66B01FBB92821C587A.asc)\n* **Isaac Z. Schlueter** \u003c\u003ci@izs.me\u003e\u003e\n  [`93C7E9E91B49E432C2F75674B0A78B0A6C481CF6`](./keys/93C7E9E91B49E432C2F75674B0A78B0A6C481CF6.asc)\n* **Italo A. Casas** \u003c\u003cme@italoacasas.com\u003e\u003e\n  [`56730D5401028683275BD23C23EFEFE93C4CFFFE`](./keys/56730D5401028683275BD23C23EFEFE93C4CFFFE.asc)\n* **James M Snell** \u003c\u003cjasnell@keybase.io\u003e\u003e\n  [`71DCFD284A79C3B38668286BC97EC7A07EDE3FC1`](./keys/71DCFD284A79C3B38668286BC97EC7A07EDE3FC1.asc)\n* **Jeremiah Senkpiel** \u003c\u003cfishrock@keybase.io\u003e\u003e\n  [`FD3A5288F042B6850C66B31F09FE44734EB7990E`](./keys/FD3A5288F042B6850C66B31F09FE44734EB7990E.asc)\n* **Juan José Arboleda** \u003c\u003csoyjuanarbol@gmail.com\u003e\u003e\n  [`61FC681DFB92A079F1685E77973F295594EC4689`](./keys/61FC681DFB92A079F1685E77973F295594EC4689.asc)\n* **Julien Gilli** \u003c\u003cjgilli@fastmail.fm\u003e\u003e\n  [`114F43EE0176B71C7BC219DD50A3051F888C628D`](./keys/114F43EE0176B71C7BC219DD50A3051F888C628D.asc)\n* **Myles Borins** \u003c\u003cmyles.borins@gmail.com\u003e\u003e\n  [`C4F0DFFF4E8C1A8236409D08E73BC641CC11F4C8`](./keys/C4F0DFFF4E8C1A8236409D08E73BC641CC11F4C8.asc)\n* **Rod Vagg** \u003c\u003crod@vagg.org\u003e\u003e\n  [`DD8F2338BAE7501E3DD5AC78C273792F7D83545D`](./keys/DD8F2338BAE7501E3DD5AC78C273792F7D83545D.asc)\n* **Ruben Bridgewater** \u003c\u003cruben@bridgewater.de\u003e\u003e\n  [`A48C2BEE680E841632CD4E44F07496B3EB3C1762`](./keys/A48C2BEE680E841632CD4E44F07496B3EB3C1762.asc)\n* **Shelley Vohr** \u003c\u003cshelley.vohr@gmail.com\u003e\u003e\n  [`B9E2F5981AA6E0CD28160D9FF13993A75599653C`](./keys/B9E2F5981AA6E0CD28160D9FF13993A75599653C.asc)\n* **Timothy J Fontaine** \u003c\u003ctjfontaine@gmail.com\u003e\u003e\n  [`7937DFD2AB06298B2293C3187D33FF9D0246406D`](./keys/7937DFD2AB06298B2293C3187D33FF9D0246406D.asc)\n\n\u003c!-- /Retired keys --\u003e\n\n## Verifying Release Packages\n\nThis repo contains the raw release signing keys in three forms:\n\n- The **keys/** directory contains the raw ASCII-armored release signing keys listed above.\n\n- The **gpg/** directory contains a GPG keyring preloaded with these release signing keys.\n\n- The **gpg-only-active-keys/** directory contains a GPG keyring preloaded with\n  the active release signing keys. Use this if you only need to verify\n  signatures of \"future\" releases.\n\nFor additional verification of both the keys' content *and* of the list of authorized signing\nkeys, you may cross-reference the list with [nodejs.org](https://nodejs.org) and attempt to\nfetch keys from alternative sources (instead of or in addition to this repo).\n\n### Using the preloaded GPG keyring\n\nFirst, clone this repo:\n\n```bash\ngit clone https://github.com/nodejs/release-keys.git\n```\n\nThen, prefix your `gpg` commands with the path to the cloned repo's **gpg/** directory.\nFor example, if you cloned the repo to **/path/to/nodejs-keys**, then the `gpg` command\nto verify a release package will look something like this:\n\n```bash\nGNUPGHOME=/path/to/release-keys/gpg gpg --verify SHASUMS256.txt.sig SHASUMS256.txt\n```\n\n### Using your own GPG keyring\n\nFirst, clone this repo:\n\n```bash\ngit clone https://github.com/nodejs/release-keys.git\n```\n\nThen, import the release signing keys from this repo into your GPG keychain by invoking\nthe **cli.sh** script in this repo. For example, immediately after cloning the repo above,\nthe following command will import all release signing keys:\n\n```bash\nrelease-keys/cli.sh import\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnodejs%2Frelease-keys","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnodejs%2Frelease-keys","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnodejs%2Frelease-keys/lists"}