Skip to content

Commit 9a7214f

Browse files
committed
Activate 'verify-signatures' by TRUE (upper case)
Do this so that Renovate does not attempt to update the file. We do it manually if necessary.
1 parent d36c3a7 commit 9a7214f

File tree

1 file changed

+107
-69
lines changed

1 file changed

+107
-69
lines changed

gradle/verification-metadata.xml

Lines changed: 107 additions & 69 deletions
Original file line numberDiff line numberDiff line change
@@ -2,100 +2,138 @@
22
<verification-metadata xmlns="https://schema.gradle.org/dependency-verification" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="https://schema.gradle.org/dependency-verification https://schema.gradle.org/dependency-verification/dependency-verification-1.3.xsd">
33
<configuration>
44
<verify-metadata>false</verify-metadata>
5-
<verify-signatures>true</verify-signatures>
5+
<!-- use 'TRUE' instead of 'true' so that Renovate ignores it: https://github.com/renovatebot/renovate/discussions/39029 -->
6+
<verify-signatures>TRUE</verify-signatures>
67
<keyring-format>armored</keyring-format>
78
<key-servers enabled="false"/>
89
<trusted-artifacts>
910
<trust file=".*-javadoc[.]jar" regex="true"/>
1011
<trust file=".*-sources[.]jar" regex="true"/>
1112
<trust file="^gradle-\d+\.\d+(?:\.\d+)?(?:-(?:rc|milestone)-\d+)?-src\.zip$" regex="true"/>
13+
<!-- explicitly trust unsigned artifacts -->
14+
<trust file="asciidoctor-gradle-base-4.0.5.jar"/>
15+
<trust file="asciidoctor-gradle-jvm-4.0.5.jar"/>
1216
</trusted-artifacts>
13-
<ignored-keys>
14-
<ignored-key id="62EBFC78FE4156D1" reason="Key couldn't be downloaded from any key server"/>
15-
</ignored-keys>
1617
<trusted-keys>
17-
<trusted-key id="05F1A5DA5701D415BEFC67FC6329ADE2B25B244B" group="io.github.pdvrieze.xmlutil"/>
18-
<trusted-key id="1BD97A6A154E7810EE0BC832E2F38302C8075E3D">
19-
<trusting group="com.gradle.publish" name="plugin-publish-plugin"/>
20-
<trusting group="org.gradle.exemplar"/>
18+
<!-- BUILD: CONVENTIONS -->
19+
<!-- ✅ Signed by the GradleX organisation (us) -->
20+
<trusted-key id="66D7CBFF956830FE9F5A723AFE6C7D77A1CE15A6" group="org.gradlex"/>
21+
22+
23+
<!-- BUILD: PLUGIN PUBLISHING - Gradle plugin publishing plugin with transitive dependency -->
24+
<!-- ✅ Signed by Gradle Inc. -->
25+
<trusted-key id="1BD97A6A154E7810EE0BC832E2F38302C8075E3D" group="com.gradle.publish" name="plugin-publish-plugin"/>
26+
<!-- ✅ Signed by ASF - Robert Scholte -->
27+
<trusted-key id="B02137D875D833D9B23392ECAE5A7FB608A0221C" group="org.apache.maven" name="maven-model"/>
28+
29+
30+
<!-- BUILD: MAVEN CENTRAL PUBLISHING - Gradle Up plugin with transitive dependency -->
31+
<!-- ✅ Signed by GradleUp project -->
32+
<trusted-key id="4857D1CE04E78FAB2A172E8F39B48E1BADDB933F" group="com.gradleup.nmcp">
33+
<trusting group="com.gradleup.nmcp"/>
34+
<trusting group="com.gradleup.gratatouille"/>
2135
</trusted-key>
22-
<trusted-key id="1D2C7EF8ADA0F794B58C7C63436902AF59EDF60E" group="dev.equo.ide" name="solstice"/>
23-
<trusted-key id="1D9866E375A1435ACE0BE0ADE3461D2D16725F94" group="com.palantir.javaformat"/>
24-
<trusted-key id="28118C070CB22A0175A2E8D43D12CA2AC19F3181">
25-
<trusting group="com.fasterxml.jackson.core"/>
26-
<trusting group="com.fasterxml.jackson.datatype"/>
27-
<trusting group="com.fasterxml.jackson.module"/>
36+
<!-- ✅ Signed by JetBrains -->
37+
<trusted-key id="E7DC75FC24FB3C8DFE8086AD3D5839A2262CBBFB" group="org.jetbrains.kotlinx"/>
38+
<!-- ✅ Signed by Paul de Vrieze - XmlUtil -->
39+
<trusted-key id="05F1A5DA5701D415BEFC67FC6329ADE2B25B244B" group="io.github.pdvrieze.xmlutil"/>
40+
41+
42+
<!-- BUILD: ANALYSIS - Gradle Develocity plugins -->
43+
<!-- ✅ Signed by Gradle Inc. -->
44+
<trusted-key id="7B79ADD11F8A779FE90FD3D0893A028475557671" group="com.gradle"/>
45+
46+
47+
<!-- TESTING - JUnit, AssertJ, and Gradle Exemplar with transitive dependencies -->
48+
<!-- ✅ Signed by JUnit - Marc Philipp -->
49+
<trusted-key id="FF6E2C001948C5F2F38B0CC385911F425EC61B51">
50+
<trusting group="junit"/>
51+
<trusting group="org.apiguardian"/>
52+
<trusting group="org.junit.jupiter"/>
53+
<trusting group="org.junit.platform"/>
54+
<trusting group="org.junit.vintage"/>
55+
<trusting group="org.opentest4j"/>
2856
</trusted-key>
57+
<!-- ✅ Signed by Hamcrest - Tom Denley -->
58+
<trusted-key id="4DB1A49729B053CAF015CEE9A6ADFC93EF34893E" group="org.hamcrest" name="hamcrest-core"/>
59+
<!-- ✅ Signed by Gradle Inc. -->
60+
<trusted-key id="1BD97A6A154E7810EE0BC832E2F38302C8075E3D" group="org.gradle.exemplar"/>
61+
<!-- ✅ Signed by ASF - Gary David Gregory -->
2962
<trusted-key id="2DB4F1EF0FA761ECC4EA935C86FDC7E2A11262CB">
63+
<trusting group="org.apache.commons"/>
3064
<trusting group="commons-codec"/>
3165
<trusting group="commons-io"/>
32-
<trusting group="org.apache.commons"/>
3366
</trusted-key>
34-
<trusted-key id="2E3A1AFFE42B5F53AF19F780BCF4173966770193" group="org.jetbrains" name="annotations"/>
35-
<trusted-key id="3448B9AECE73A41DC11FEE9ADDF3944950267CD1" group="org.functionaljava" name="functionaljava"/>
67+
<!-- ✅ Signed by Andrea Peruffo - com.typesafe.config -->
68+
<trusted-key id="E88BF2559874BA889D34357C0555B3BA1CA4ECF9" group="com.typesafe" name="config"/>
69+
<!-- ✅ Signed by AssertJ -->
70+
<trusted-key id="BE685132AFD2740D9095F9040CC0B712FEE75827" group="org.assertj" name="assertj-core"/>
71+
<!-- ✅ Signed by Rafael Winterhalter - ByteBuddy -->
72+
<trusted-key id="A7892505CF1A58076453E52D7999BEFBA1039E8B" group="net.bytebuddy" name="byte-buddy"/>
73+
74+
75+
<!-- CODE DOCUMENTATION - Asciidoctor Gradle Plugin with transitive dependencies -->
76+
<!-- ✅ Signed by Schalk W. Cronjé - ysb33r -->
77+
<trusted-key id="EA022560A81E5BD48DB3D18B54AC8E2D98CFEAC6" group="org.ysb33r.gradle"/>
78+
<!-- ✅ Signed by Robert Panzer - AsciidoctorJ -->
79+
<trusted-key id="AD296CA014321485EB6780FF8B8E0CB0F6A7657E" group="org.asciidoctor"/>
80+
<!-- ✅ Signed by Lasse Collin - Tukaani -->
3681
<trusted-key id="3690C240CE51B4670D30AD1C38EE757D69184620" group="org.tukaani" name="xz"/>
82+
83+
84+
<!-- CODE FORMATTING - Spotless Gradle Plugin with transitive dependencies -->
85+
<!-- ✅ Signed by DiffPlug LLC -->
86+
<trusted-key id="A31DDE881C3E3C4C985BD0D02C7F998F4272C851" group="com.diffplug.spotless"/>
87+
<!-- ✅ Signed by DiffPlug LLC -->
3788
<trusted-key id="4797B4F5DCC46CEA61059071A1AE06236CA2BA62" group="com.diffplug.durian"/>
38-
<trusted-key id="4857D1CE04E78FAB2A172E8F39B48E1BADDB933F">
39-
<trusting group="com.gradleup.gratatouille"/>
40-
<trusting group="com.gradleup.nmcp"/>
41-
</trusted-key>
42-
<trusted-key id="4DB1A49729B053CAF015CEE9A6ADFC93EF34893E" group="org.hamcrest" name="hamcrest-core"/>
43-
<trusted-key id="648190996EC0930A6D7D49A978178478013521D0" group="com.facebook" name="ktfmt"/>
44-
<trusted-key id="66D7CBFF956830FE9F5A723AFE6C7D77A1CE15A6" group="org.gradlex"/>
89+
<!-- ✅ Signed by JetBrains -->
4590
<trusted-key id="6F538074CCEBF35F28AF9B066A0975F8B1127B83" group="org.jetbrains.kotlin"/>
46-
<trusted-key id="78DA3333F653B1C54A938BE24DB7BC57DFDBCEA4" group="net.java.dev.jna" name="jna"/>
47-
<trusted-key id="7B79ADD11F8A779FE90FD3D0893A028475557671" group="com.gradle"/>
91+
<!-- ✅ Signed by Square (squareup.com) -->
92+
<trusted-key id="DBD744ACE7ADE6AA50DD591F66B50994442D2D40">
93+
<trusting group="com.squareup.okhttp3"/>
94+
<trusting group="com.squareup.okio"/>
95+
</trusted-key>
96+
<!-- ✅ Signed by Matthias Sohn - JGit -->
4897
<trusted-key id="7C669810892CBD3148FA92995B05CCDE140C2876" group="org.eclipse.jgit" name="org.eclipse.jgit"/>
98+
<!-- ✅ Signed by Niall Gallagher - concurrent-trees -->
99+
<trusted-key id="A9789342F598AD5B1175EF357EB97D110DFADD60" group="com.googlecode.concurrent-trees" name="concurrent-trees"/>
100+
<!-- ✅ Signed by JetBrains -->
101+
<trusted-key id="2E3A1AFFE42B5F53AF19F780BCF4173966770193" group="org.jetbrains" name="annotations"/>
102+
<!-- 🤔 Signed by Sebastian Sampaoli <[email protected]> -->
103+
<trusted-key id="1D2C7EF8ADA0F794B58C7C63436902AF59EDF60E" group="dev.equo.ide" name="solstice"/>
104+
<!-- 🤔 Signed by ??? -->
105+
<trusted-key id="9E3044071B758EBCB7E45673700E4F39BC05364B" group="org.eclipse.platform" name="org.eclipse.osgi"/>
106+
<!-- 🤔 Signed by Bintray/JFrog -->
49107
<trusted-key id="8756C4F765C9AC3CB6B85D62379CE192D401AB61">
50-
<trusting group="com.diffplug.durian"/>
51108
<trusting group="org.jetbrains.intellij.deps"/>
109+
<trusting group="com.diffplug.durian"/>
52110
</trusted-key>
53-
<trusted-key id="9E3044071B758EBCB7E45673700E4F39BC05364B" group="org.eclipse.platform" name="org.eclipse.osgi"/>
54-
<trusted-key id="A31DDE881C3E3C4C985BD0D02C7F998F4272C851" group="com.diffplug.spotless"/>
55-
<trusted-key id="A7892505CF1A58076453E52D7999BEFBA1039E8B" group="net.bytebuddy" name="byte-buddy"/>
56-
<trusted-key id="A9789342F598AD5B1175EF357EB97D110DFADD60" group="com.googlecode.concurrent-trees" name="concurrent-trees"/>
57-
<trusted-key id="AD296CA014321485EB6780FF8B8E0CB0F6A7657E" group="org.asciidoctor"/>
58-
<trusted-key id="B02137D875D833D9B23392ECAE5A7FB608A0221C" group="org.apache.maven" name="maven-model"/>
59-
<trusted-key id="BDB5FA4FE719D787FB3D3197F6D4A1D411E9D1AE" group="com.google.guava" name="guava"/>
60-
<trusted-key id="BE685132AFD2740D9095F9040CC0B712FEE75827" group="org.assertj" name="assertj-core"/>
61-
<trusted-key id="DBD744ACE7ADE6AA50DD591F66B50994442D2D40">
62-
<trusting group="com.squareup.okhttp3"/>
63-
<trusting group="com.squareup.okio"/>
111+
112+
113+
<!-- CODE FORMATTING - Palantir Java formatter with transitive dependencies -->
114+
<!-- ✅ Signed by Palantir -->
115+
<trusted-key id="1D9866E375A1435ACE0BE0ADE3461D2D16725F94" group="com.palantir.javaformat"/>
116+
<!-- ✅ Signed by Tatu Saloranta - Jackson -->
117+
<trusted-key id="28118C070CB22A0175A2E8D43D12CA2AC19F3181">
118+
<trusting group="com.fasterxml.jackson.core"/>
119+
<trusting group="com.fasterxml.jackson.datatype"/>
120+
<trusting group="com.fasterxml.jackson.module"/>
64121
</trusted-key>
65-
<trusted-key id="E7DC75FC24FB3C8DFE8086AD3D5839A2262CBBFB" group="org.jetbrains.kotlinx"/>
66-
<trusted-key id="E88BF2559874BA889D34357C0555B3BA1CA4ECF9" group="com.typesafe" name="config"/>
67-
<trusted-key id="EA022560A81E5BD48DB3D18B54AC8E2D98CFEAC6" group="org.ysb33r.gradle"/>
122+
<!-- ✅ Signed by Christopher Povirk - Guava -->
123+
<trusted-key id="BDB5FA4FE719D787FB3D3197F6D4A1D411E9D1AE" group="com.google.guava" name="guava"/>
124+
<!-- ✅ Jean-Baptiste Giraudeau - Functional Java -->
125+
<trusted-key id="3448B9AECE73A41DC11FEE9ADDF3944950267CD1" group="org.functionaljava" name="functionaljava"/>
126+
127+
128+
<!-- CODE FORMATTING - ktfmt with transitive dependencies -->
129+
<!-- ✅ Signed by Ktfmt Team -->
130+
<trusted-key id="648190996EC0930A6D7D49A978178478013521D0" group="com.facebook" name="ktfmt"/>
131+
<!-- ✅ Signed by Liam Miller-Cushon (Error Prone releases) -->
68132
<trusted-key id="EE0CA873074092F806F59B65D364ABAA39A47320" group="com.google.googlejavaformat" name="google-java-format"/>
69-
<trusted-key id="FF6E2C001948C5F2F38B0CC385911F425EC61B51">
70-
<trusting group="junit"/>
71-
<trusting group="org.apiguardian"/>
72-
<trusting group="org.junit.jupiter"/>
73-
<trusting group="org.junit.platform"/>
74-
<trusting group="org.junit.vintage"/>
75-
<trusting group="org.opentest4j"/>
76-
</trusted-key>
133+
<!-- ✅ Signed by Timothy Wall - Java Native Access (JNA) -->
134+
<trusted-key id="78DA3333F653B1C54A938BE24DB7BC57DFDBCEA4" group="net.java.dev.jna" name="jna"/>
77135
</trusted-keys>
78136
</configuration>
79137
<components>
80-
<component group="com.beust" name="jcommander" version="1.82">
81-
<artifact name="jcommander-1.82.jar">
82-
<pgp value="C70B844F002F21F6D2B9C87522E44AC0622B91C3"/>
83-
</artifact>
84-
</component>
85-
<component group="org.asciidoctor" name="asciidoctor-gradle-base" version="4.0.5">
86-
<artifact name="asciidoctor-gradle-base-4.0.5.jar">
87-
<sha256 value="3b0a5c953c98977da3cec1bfd66c0f7438e3e07c06bda00abae8c53e4dd2185a" origin="Downloaded the file from https://plugins.gradle.org/m2/org/asciidoctor/asciidoctor-gradle-base/4.0.5 and generated the checksum locally" reason="Artifact is not signed"/>
88-
</artifact>
89-
</component>
90-
<component group="org.asciidoctor" name="asciidoctor-gradle-jvm" version="4.0.5">
91-
<artifact name="asciidoctor-gradle-jvm-4.0.5.jar">
92-
<sha256 value="3e020e7f350cb6ff2658ff124ea63d42da3dacf6da3b71efe4c7670413369ce9" origin="Downloaded the file from https://plugins.gradle.org/m2/org/asciidoctor/asciidoctor-gradle-jvm/4.0.5 and generated the checksum locally" reason="Artifact is not signed"/>
93-
</artifact>
94-
</component>
95-
<component group="org.jruby" name="jruby-complete" version="9.3.8.0">
96-
<artifact name="jruby-complete-9.3.8.0.jar">
97-
<sha256 value="b574542f75c71d543ae057a707ca9840e778d62ab6da610e94cd7bbfa5eef5d5" origin="Generated by Gradle" reason="A key couldn't be downloaded"/>
98-
</artifact>
99-
</component>
100138
</components>
101139
</verification-metadata>

0 commit comments

Comments
 (0)