Changing the Signing Key for Release Bundles v2
Learn how to change the signing key for a Release Bundle v2 on the JFrog Platform.
RLM Deprecation
As of July 31, 2026, all feature development, patches, and security fixes for Release Lifecycle Management will end, except for critical security fixes. RLM End of Life is currently scheduled for January 31, 2028. For more information, see JFrog Release Lifecycle Management Deprecation - End of Life.
You can change the signing key used to sign an existing Release Bundle v2 when required. For example, you might need a new key if the original key is compromised or if responsibility for the Release Bundle moves to a different department or team in your organization.
You can change the key when you create a new version of an existing Release Bundle or when you promote a Release Bundle v2 version.
Release Bundle v2 distribution, however, always uses the key that was used to create the Release Bundle version.
Note
You can also change the signing key for a Release Bundle v2 using the Update Key Pair REST API.
Related Topics
- Creating Release Bundles (v2)
- Release Lifecycle Management Setup
- Create a Release Bundle v2 in the JFrog Platform UI
- Promote a Release Bundle v2 Version
- Understanding Release Bundles v2
Updated 11 days ago
