Verifies the PGP signatures of resolved dependencies, but only for a whitelist of
groupIds (org.openmrs by default) against the keys allowed to sign them. Artifacts outside
the whitelist are ignored, so the check is version-independent and free of the third-party
signature treadmill.
Latest Versions
1 versions →| Version | Vulnerabilities | Usages | Date | |
|---|---|---|---|---|
1.0.x | 1.0.0 |
0
| Jun 23, 2026 |