NAME
App::FuguBench::Keys - the embedded release keys of fugubench
SYNOPSIS
use App::FuguBench::Keys;
for my $pair (App::FuguBench::Keys->keys) {
my ($name, $body) = @$pair;
}
DESCRIPTION
App::FuguBench::Keys holds the release public keys of the organization. The program embeds them in this module, so no file of the host decides what a release trusts. The keys are those of deps/KEYS.txt of the org pack, and t/fugubench/keys.t holds this module to that file.
The deps verb never reads this list. It verifies with the keys of the consumer, because a consumer decides what it trusts.
keys
keys returns the [name, body] pair of each release key. A name is the name of the key line, and a body is the 56 base64 characters of a signify public key: the second line of a .pub file. A public key carries no secret, so the list is source.
THE TRUST ORDER
The list order is the line order of deps/KEYS.txt, which is the trust order. The current key comes first.
A rotation is a release of the program, and this list follows deps/KEYS.txt. A release therefore carries the keys that the file held at that release, and an installed program can lack the key of a later release. update then names the install command, and the operator installs the program again.
RETURN VALUES
keys returns a list of array references, one for each release key.
SEE ALSO
App::FuguBench, App::FuguBench::Deps, Fugu::Signify
AUTHORS
Dick Olsson <hi@senzilla.io>