NAME

App::FuguBench::Keys - the embedded release keys of fugubench

SYNOPSIS

use App::FuguBench::Keys;

for my $pair (App::FuguBench::Keys->keys) {
    my ($name, $body) = @$pair;
}

DESCRIPTION

App::FuguBench::Keys holds the release public keys of the organization. The program embeds them in this module, so no file of the host decides what a release trusts. The keys are those of deps/KEYS.txt of the org pack, and t/fugubench/keys.t holds this module to that file.

The deps verb never reads this list. It verifies with the keys of the consumer, because a consumer decides what it trusts.

keys

keys returns the [name, body] pair of each release key. A name is the name of the key line, and a body is the 56 base64 characters of a signify public key: the second line of a .pub file. A public key carries no secret, so the list is source.

THE TRUST ORDER

The list order is the line order of deps/KEYS.txt, which is the trust order. The current key comes first.

A rotation is a release of the program, and this list follows deps/KEYS.txt. A release therefore carries the keys that the file held at that release, and an installed program can lack the key of a later release. update then names the install command, and the operator installs the program again.

RETURN VALUES

keys returns a list of array references, one for each release key.

SEE ALSO

App::FuguBench, App::FuguBench::Deps, Fugu::Signify

AUTHORS

Dick Olsson <hi@senzilla.io>