From 7c305a49008a5846f6b71e0755609132282500d3 Mon Sep 17 00:00:00 2001 From: Aviv Keller <38299977+RedYetiDev@users.noreply.github.com> Date: Mon, 5 Aug 2024 12:39:58 -0400 Subject: [PATCH] doc, meta: replace command with link to keys MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit PR-URL: https://github.com/nodejs/node/pull/53745 Reviewed-By: Ulises Gascón Reviewed-By: Beth Griggs Reviewed-By: Richard Lau --- README.md | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index d11ee561bedba5..ab224f0cc16b12 100644 --- a/README.md +++ b/README.md @@ -112,14 +112,9 @@ grep node-vx.y.z.tar.gz SHASUMS256.txt | sha256sum -c - For Current and LTS, the GPG detached signature of `SHASUMS256.txt` is in `SHASUMS256.txt.sig`. You can use it with `gpg` to verify the integrity of `SHASUMS256.txt`. You will first need to import -[the GPG keys of individuals authorized to create releases](#release-keys). To -import the keys: +[the GPG keys of individuals authorized to create releases](#release-keys). -```bash -gpg --keyserver hkps://keys.openpgp.org --recv-keys 4ED778F539E3634C779C87C6D7062848A1AB005C -``` - -See [Release keys](#release-keys) for a script to import active release keys. +See [Release keys](#release-keys) for commands to import active release keys. Next, download the `SHASUMS256.txt.sig` for the release: