Repository navigation
Node 24.12.0 release key not listed in README #61022
Description
Activity
86C8D74642E67846F8E120284DAA80D1E737BC9F's fingerprint is 8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600 (see https://keys.openpgp.org/search?q=86C8D74642E67846F8E120284DAA80D1E737BC9F), which is listed on the README:
Line 786 in 29477c5
Primary GPG keys for Node.js Releasers (some Releasers sign with subkeys):
Lines 794 to 795 in 29477c5
* **Michaël Zasso** <<targos@protonmail.com>> `8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600` AFAICT the README is up-to-date.
Ah... both
gpg --keyserver hkps://keys.openpgp.org --recv-keys 8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600and
gpg --keyserver hkps://keys.openpgp.org --recv-keys 86C8D74642E67846F8E120284DAA80D1E737BC9Fwork.
The error you get (via mise at least) without installing it only mentions 86C8D74642E67846F8E120284DAA80D1E737BC9F though, so that's what I went to the node readme to look up. That said, I'm fine with closing this out given this, albeit I expect others to run into this.
gpg: Signature made Wed Dec 10 11:44:57 2025 EST gpg: using EDDSA key 86C8D74642E67846F8E120284DAA80D1E737BC9F gpg: Can't check signature: No public key mise ERROR gpg failed gpg: Signature made Wed Dec 10 11:44:57 2025 EST gpg: using EDDSA key 86C8D74642E67846F8E120284DAA80D1E737BC9F gpg: Can't check signature: No public key mise ERROR Failed to install core:node@24.12.0: 0: gpg exited with non-zero status: exit code 2Reacted by Afx31This has affected unofficial-builds and will probably also affect https://github.com/nodejs/docker-node.
I should note that a new key is not mentioned in the changelog. Given it’s effectively a breaking change since multiple ecosystems are broken over it, I think that’s a miss. As is, for us to use 24.12.0, we need to update 50+ some GitHub actions and CI scripts at my company alone to pull keys from new places across disparate projects and repositories, which we’ve never had to do before in our company history.
Mise’s discussion is at: jdx/mise#7237
Reacted by Joshua Sleeper and Chris Croome- added a commit that references this issue
on Dec 18, 2025 - added a commit that references this issue
on Mar 19, 2026 github-actions commented
on Jul 10, 2026 on Jul 10, 2026 – with GitHub ActionsContributorMore actionsThis issue has been marked as stale due to 210 days of inactivity.
It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.- addedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Jul 10, 2026
Version
24.12.0
Platform
Subsystem
No response
What steps will reproduce the bug?
install node 24.12.0 - notice it has a new release key that fails gpg without preinstalling it
Look at https://github.com/nodejs/node/blob/main/README.md#release-keys -- 86C8D74642E67846F8E120284DAA80D1E737BC9F is not listed
How often does it reproduce? Is there a required condition?
100% on Node 24.12.0
What is the expected behavior? Why is that the expected behavior?
Should be able to install Node 24.12.0 just like 24.11.1 - not need to do new GPG Import of public keys across ecosystem, but at minimum, it should be documented
What do you see instead?
86C8D74642E67846F8E120284DAA80D1E737BC9F is not listed in README
Additional information
No response