Verifies the PGP signatures of resolved dependencies, but only for a whitelist of groupIds (org.openmrs by default) against the keys allowed to sign them. Artifacts outside the whitelist are ignored, so the check is version-independent and free of the third-party signature treadmill.

Latest Versions

1 versions →
VersionVulnerabilitiesUsagesDate
1.0.x
1.0.0
0
Jun 23, 2026
1 versions →