Skip to content

Debian repo: New GPG key #9218

@Daniel15

Description

@Daniel15

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Yarn has switched to a new signing key. See #9216 for more details.

Old key:
pub rsa4096 2016-10-05
72ECF46A56B4AD39C907BBB71646B01B86E50310
uid Yarn Packaging yarn@dan.cx
sub rsa4096
DEE0F07B347CD8202105B20C23E7166788B63E1E

New key:
pub ed25519 2026-01-28
4EF8150F4F2D7DE44F1DFF0BB42879CC6B38E118
uid Yarn Packaging (2026) yarn@dan.cx
sub ed25519 2026-01-28
FF7CB5667B542092084BBDC562D54FD4003F6525

Run the following command to update the key:

curl -sS https://dl.yarnpkg.com/debian/pubkey.gpg | gpg --dearmor | sudo tee /etc/apt/keyrings/yarn-archive-keyring.gpg > /dev/null

I have cross-signed these keys to establish a chain of trust, and this message has also been signed with both keys.

During the transition period, the public key at http://dl.yarnpkg.com/debian/pubkey.gpg will contain both the old and the new key. Eventually, the old key will be revoked and only the new key will be in use.

I apologise for the inconvenience, but this was necessary in order to ensure that our Debian repo continues to work properly.

2026-01-28
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQT/fLVme1QgkghLvcVi1U/UAD9lJQUCaXqBQwAKCRBi1U/UAD9l
JR5YAQD9ZvkhWrkbFI4a6HxhjJhcc3MKS7zfbqJPmo3PJDxonAD+NnDvdSZ4nBHh
hb+8Z42hEsucE8QdClP8jv7xBdKw2guJAjMEAQEKAB0WIQRtmEkMbxrN3USORZVP
d2eTaUdbqgUCaXqBQwAKCRBPd2eTaUdbqpIkD/0UTRXmngAfQ1cTKInJPNQuvRKD
V94qqenc5lQgoP5CAcBjHaWC9o+fSVGAQS20Y/e1LS4KovkeuR5YoWE9QxudowHS
mCJRG29HZoGoroevvJDqUnCwJC1uctP/4NLAKp6pJBm1p71OZSimaZWqhKRHQN9d
HS7JQ45xU1SnCGl7LXxc+PI1iczqr5DwXgnwGZKnrEtZi7EwwEWfFyXvhTbqg8jt
LsKyxm1WWHwNzxXIi5IKl8enu6yb5YBSDMIXLdhc2rh5uG5DL2DsFC/vPv5rdZHf
cqo1Lvq0uvHZ8C06TTea9n1vGaIxAF5hZXSmGn4MggDhNx6kv8WXk9yqITParqMj
ePyN5L2U07/InnlAgtT8YU5e8sSK+9t+HhE9kBk5VBZkHycXklgPrYIX+PuYmvID
kwCi/e0PBwgRTIaklX2e2tuDSVjZZcptWtiHq2pYHv66fcRImAkEZOf1ZlPZ4Jv8
hwjkiBg0iW3hIRznSDysRGgEdctAySv2bC78BmsVvSvMJdl0F8jQ/l5biDwjFC9N
9UagyepOWVFMcfY5y9OmdV/CFtZ6gblUknIu//UXf7zRsFBKQ0P8/Ss6TM5BQFlw
6+iFeLAR/ZuYUiCIaQS2k9bYCzwD6VHkcUB+Xf/Uol5cYYa5idN6BYg5FRBGjol4
lS2lEpdMp+U6wyvHzA==
=GwFQ
-----END PGP SIGNATURE-----

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions