Changing the Signing Key for Release Bundles v2

Learn how to change the signing key for a Release Bundle v2 on the JFrog Platform.

RLM Deprecation

As of July 31, 2026, all feature development, patches, and security fixes for Release Lifecycle Management will end, except for critical security fixes. RLM End of Life is currently scheduled for January 31, 2028. For more information, see JFrog Release Lifecycle Management Deprecation - End of Life.

You can change the signing key used to sign an existing Release Bundle v2 when required. For example, you might need a new key if the original key is compromised or if responsibility for the Release Bundle moves to a different department or team in your organization.

You can change the key when you create a new version of an existing Release Bundle or when you promote a Release Bundle v2 version.

Release Bundle v2 distribution, however, always uses the key that was used to create the Release Bundle version.

📘

Note

You can also change the signing key for a Release Bundle v2 using the Update Key Pair REST API.

Related Topics



Did this page help you?