#1960·anubis

Not possible to verify PGP signatures

Author: hax0rbana-adamCreated Sep 15, 2026Updated Sep 17, 2026

Describe the bug

All of the releases are PGP signed, but there's no instructions on where the PGP key is that can be used to verify these signatures. There's no mention of PGP on the website, and a search for PGP in this repo turned up nothing.

At a minimum, the public PGP key should be published somewhere.

Ideally, it would also appear in the documentation. Documenting the PGP command to actually do the verification would be nice, but it's optional. It's reasonable to assume that someone wanting to do the verification either knows how to use PGP, or can look it up elsewhere.

Steps to reproduce

Follow any install guide or read the other documentation. Note the it doesn't mention where to find the public PGP key.

Expected behavior

There's a key that enables users to check the published PGP signatures.

Your operating system and its version.

Debian 13

Your browser and its version.

Firefox 140

Additional context

No response