phpboyscout.uk

Public keys

The OpenPGP keys that sign PHP Boy Scout software releases, and the one you encrypt a security report to. They're published over Web Key Directory (WKD), so your tools can find and trust them without you hunting down a keyserver.

Fetch a key

WKD resolves straight from the email address — no fingerprint to copy by hand:

gpg --locate-keys release@phpboyscout.uk

Then verify a signed release the usual way:

gpg --verify mytool_1.2.3_checksums.txt.asc mytool_1.2.3_checksums.txt

Every address below works the same way. They are key identifiers first; if you want a reply from a person, write to security@phpboyscout.uk.

Reporting a vulnerability

One key here is not for verifying our software. It is for encrypting something to us, so a report is unreadable in transit and unreadable at rest in the ticket that carries it.

PHP Boy Scout Securitycontact

security@phpboyscout.uk · encrypted vulnerability reports

Certification primary · RSA-4096 · created 2026-08-10

C889 A6B1 C095 8B51 95EE  8BBB A3EE 60A9 0E31 3264

Encryption subkey · ECDH NIST P-256 · created 2026-08-10

F364 8882 C6EA 7B41 EFBA  DA49 050F 18DF 4DE0 F6E5
gpg --locate-keys security@phpboyscout.uk

What to send, and where it goes, is on the security policy page and in security.txt. Please don't open a public issue for a security problem.

Release signing keys

Estate-wide identities. release@ signs across projects; release-v2@ is the current rotation and carries the superseded keys alongside the new one, so binaries pinning an older fingerprint keep verifying.

PHP Boy Scout Releasecurrent

release-v2@phpboyscout.uk · the estate release-signing identity

Ed25519 · created 2026-06-08

2B26 6584 0904 7ED0 8B56  CEBD CF5B 8DBB 5D9F 19C2

RSA-4096 · created 2026-07-24

E969 F9AB 1678 97D8 76B6  A93A A44A 36F8 D7AC F36D

RSA-4096 · created 2026-06-08 · superseded, still served

6E20 72BB F83D FAAF 0063  00C4 95DD AC33 3C37 AA35
gpg --locate-keys release-v2@phpboyscout.uk

PHP Boy Scout Releasev1

release@phpboyscout.uk · the original identity, still resolvable

Ed25519 · created 2026-06-08

2B26 6584 0904 7ED0 8B56  CEBD CF5B 8DBB 5D9F 19C2

RSA-4096 · created 2026-06-08

6E20 72BB F83D FAAF 0063  00C4 95DD AC33 3C37 AA35

Per-project release keys

A project with its own signing key gets its own identity, so rotating one project's key touches nothing else.

ffmpeg-wasi Release Signingcurrent

ffmpeg-wasi-release-v2@phpboyscout.uk

RSA-4096 · created 2026-07-24

4C96 ECB3 5C74 4661 9FF7  8EB1 ED13 44E5 76B7 BBBF

RSA-4096 · created 2026-06-30 · superseded, still served

7108 81C1 DDAE ABD1 38E5  3004 A216 6E59 EB60 60E1
gpg --locate-keys ffmpeg-wasi-release-v2@phpboyscout.uk

ffmpeg-wasi Release Signingv1

ffmpeg-wasi-release@phpboyscout.uk

RSA-4096 · created 2026-06-30

7108 81C1 DDAE ABD1 38E5  3004 A216 6E59 EB60 60E1

krites Release Signing

krites-release@phpboyscout.uk

RSA-4096 · created 2026-07-26

329F 3314 FA1D 317E DFCC  ABC2 8E45 CA53 DB15 0302

krites-models Release Signing

krites-models-release@phpboyscout.uk

RSA-4096 · created 2026-07-24

2CE9 9F15 40FA 0550 EE5D  90F0 61B4 A9D0 E419 A73C

Artifacts Release Signing

artifacts-release@phpboyscout.uk

RSA-4096 · created 2026-08-14

544E 64F3 B875 61D5 6739  3336 34A7 11C4 B9EA A99A

Colophon Release Signing

colophon-release@phpboyscout.uk

RSA-4096 · created 2026-08-27

89E1 B4FE 47DD F365 D19C  F760 5BBB F192 43C7 1608

Everything served here, at a glance

AddressKeys in the bucketWKD hash
security@RSA-4096 primary + ECDH P-256 subkeyt5s8ztdbon8yzntexy6oz5y48etqsnbb
release-v2@Ed25519, RSA-4096 ×2yxidni38ndxos3irk9hcm9bjnnemdx8r
release@Ed25519, RSA-4096y84sdmnksfqswe7fxf5mzjg53tbdz8f5
ffmpeg-wasi-release-v2@RSA-4096 ×2wrf4auwd8jjjxjq6ymkj8a1n4j1mathw
ffmpeg-wasi-release@RSA-4096914cy8ejdzz5xfkyzpennhzja3cedi1a
krites-release@RSA-40968iqmwgrtibiqphio1rr4da61y9qpgbo7
krites-models-release@RSA-40966nznzczi3pgr6j4y1h5zd4gp3jwhy6xr
artifacts-release@RSA-4096bmjuic83t1ja8mwuaxdx1c6k1w1ktprs
colophon-release@RSA-4096b9nta9k5o85gahca7s7pick4zjk9x6qc

All under /.well-known/openpgpkey/phpboyscout.uk/hu/. You never need these paths to look a key up — they are here so a fetch can be spot-checked by hand. Compute one yourself with gpg-wks-client --print-wkd-hash <address>.

Not OpenPGP: the minisign key

Rust consumers (cargo-binstall, rtb-update) pin a minisign key rather than an OpenPGP one. It has no WKD representation, so it is served as a plain file from this same host:

curl -sS https://openpgpkey.phpboyscout.uk/minisign/rust-tool-base/v1.pub

rust-tool-base artefact signingminisign

Ed25519 · key ID A49B21E9A62ED649 · valid from 2026-08-01

RWSkmyHppi7WSWp8Mii3RJByLf0eLckGPVajCrpX+zRD/3WWhXCibJ7y

The machine-readable manifest of non-OpenPGP keys is keys.json.

How to trust these

Don't take this page's word for it. The point of WKD is that the key travels with the domain, and a second, independent copy is cross-checked so a single compromised account can't quietly swap it. A verifier that fetches both and refuses to proceed when the fingerprints disagree is doing the work; a page listing fingerprints is not.

The reasoning is written up on the blog: Publish your key where they can't touch it and A signature the platform can't forge.