phpboyscout.uk
The OpenPGP keys that sign PHP Boy Scout software releases, and the one you encrypt a security report to. They're published over Web Key Directory (WKD), so your tools can find and trust them without you hunting down a keyserver.
WKD resolves straight from the email address — no fingerprint to copy by hand:
gpg --locate-keys release@phpboyscout.uk
Then verify a signed release the usual way:
gpg --verify mytool_1.2.3_checksums.txt.asc mytool_1.2.3_checksums.txt
Every address below works the same way. They are key identifiers first; if you
want a reply from a person, write to security@phpboyscout.uk.
One key here is not for verifying our software. It is for encrypting something to us, so a report is unreadable in transit and unreadable at rest in the ticket that carries it.
gpg --locate-keys security@phpboyscout.uk
What to send, and where it goes, is on the security policy page and in security.txt. Please don't open a public issue for a security problem.
Estate-wide identities. release@ signs across projects;
release-v2@ is the current rotation and carries the superseded keys alongside the
new one, so binaries pinning an older fingerprint keep verifying.
gpg --locate-keys release-v2@phpboyscout.uk
A project with its own signing key gets its own identity, so rotating one project's key touches nothing else.
gpg --locate-keys ffmpeg-wasi-release-v2@phpboyscout.uk
| Address | Keys in the bucket | WKD hash |
|---|---|---|
| security@ | RSA-4096 primary + ECDH P-256 subkey | t5s8ztdbon8yzntexy6oz5y48etqsnbb |
| release-v2@ | Ed25519, RSA-4096 ×2 | yxidni38ndxos3irk9hcm9bjnnemdx8r |
| release@ | Ed25519, RSA-4096 | y84sdmnksfqswe7fxf5mzjg53tbdz8f5 |
| ffmpeg-wasi-release-v2@ | RSA-4096 ×2 | wrf4auwd8jjjxjq6ymkj8a1n4j1mathw |
| ffmpeg-wasi-release@ | RSA-4096 | 914cy8ejdzz5xfkyzpennhzja3cedi1a |
| krites-release@ | RSA-4096 | 8iqmwgrtibiqphio1rr4da61y9qpgbo7 |
| krites-models-release@ | RSA-4096 | 6nznzczi3pgr6j4y1h5zd4gp3jwhy6xr |
| artifacts-release@ | RSA-4096 | bmjuic83t1ja8mwuaxdx1c6k1w1ktprs |
| colophon-release@ | RSA-4096 | b9nta9k5o85gahca7s7pick4zjk9x6qc |
All under
/.well-known/openpgpkey/phpboyscout.uk/hu/. You never need these paths to look a
key up — they are here so a fetch can be spot-checked by hand. Compute one yourself with
gpg-wks-client --print-wkd-hash <address>.
Rust consumers (cargo-binstall, rtb-update) pin a minisign key rather than an
OpenPGP one. It has no WKD representation, so it is served as a plain file from this same host:
curl -sS https://openpgpkey.phpboyscout.uk/minisign/rust-tool-base/v1.pub
The machine-readable manifest of non-OpenPGP keys is keys.json.
Don't take this page's word for it. The point of WKD is that the key travels with the domain, and a second, independent copy is cross-checked so a single compromised account can't quietly swap it. A verifier that fetches both and refuses to proceed when the fingerprints disagree is doing the work; a page listing fingerprints is not.
The reasoning is written up on the blog: Publish your key where they can't touch it and A signature the platform can't forge.