Skip to content

Node 24.12.0 release key not listed in README #61022

Description

@broksonic21

Version

24.12.0

Platform


Subsystem

No response

What steps will reproduce the bug?

install node 24.12.0 - notice it has a new release key that fails gpg without preinstalling it

gpg: Signature made Wed Dec 10 11:44:57 2025 EST
gpg:                using EDDSA key 86C8D74642E67846F8E120284DAA80D1E737BC9F
gpg: Can't check signature: No public key
mise ERROR gpg failed
gpg: Signature made Wed Dec 10 11:44:57 2025 EST
gpg:                using EDDSA key 86C8D74642E67846F8E120284DAA80D1E737BC9F
gpg: Can't check signature: No public key
mise ERROR Failed to install core:node@24:
   0: gpg exited with non-zero status: exit code 2

Look at https://github.com/nodejs/node/blob/main/README.md#release-keys -- 86C8D74642E67846F8E120284DAA80D1E737BC9F is not listed

How often does it reproduce? Is there a required condition?

100% on Node 24.12.0

What is the expected behavior? Why is that the expected behavior?

Should be able to install Node 24.12.0 just like 24.11.1 - not need to do new GPG Import of public keys across ecosystem, but at minimum, it should be documented

What do you see instead?

86C8D74642E67846F8E120284DAA80D1E737BC9F is not listed in README

Additional information

No response

Activity

  1. aduh95 commented on Dec 11, 2025

    @aduh95
    Contributor

    86C8D74642E67846F8E120284DAA80D1E737BC9F's fingerprint is 8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600 (see https://keys.openpgp.org/search?q=86C8D74642E67846F8E120284DAA80D1E737BC9F), which is listed on the README:

    node/README.md

    Line 786 in 29477c5

    Primary GPG keys for Node.js Releasers (some Releasers sign with subkeys):

    node/README.md

    Lines 794 to 795 in 29477c5

    * **Michaël Zasso** <<targos@protonmail.com>>
    `8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600`

    AFAICT the README is up-to-date.

  2. broksonic21 commented on Dec 11, 2025

    @broksonic21
    Author

    Ah... both

    gpg --keyserver hkps://keys.openpgp.org --recv-keys 8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600

    and

    gpg --keyserver hkps://keys.openpgp.org --recv-keys 86C8D74642E67846F8E120284DAA80D1E737BC9F

    work.

    The error you get (via mise at least) without installing it only mentions 86C8D74642E67846F8E120284DAA80D1E737BC9F though, so that's what I went to the node readme to look up. That said, I'm fine with closing this out given this, albeit I expect others to run into this.

    gpg: Signature made Wed Dec 10 11:44:57 2025 EST
    gpg:                using EDDSA key 86C8D74642E67846F8E120284DAA80D1E737BC9F
    gpg: Can't check signature: No public key
    mise ERROR gpg failed
    gpg: Signature made Wed Dec 10 11:44:57 2025 EST
    gpg:                using EDDSA key 86C8D74642E67846F8E120284DAA80D1E737BC9F
    gpg: Can't check signature: No public key
    mise ERROR Failed to install core:node@24.12.0:
       0: gpg exited with non-zero status: exit code 2
    
  3. richardlau commented on Dec 11, 2025

    @richardlau
    Member
  4. MikeMcC399 commented on Dec 11, 2025

    @MikeMcC399
  5. broksonic21 commented on Dec 11, 2025

    @broksonic21
    Author

    I should note that a new key is not mentioned in the changelog. Given it’s effectively a breaking change since multiple ecosystems are broken over it, I think that’s a miss. As is, for us to use 24.12.0, we need to update 50+ some GitHub actions and CI scripts at my company alone to pull keys from new places across disparate projects and repositories, which we’ve never had to do before in our company history.

    https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V24.md#2025-12-10-version-24120-krypton-lts-targos

    Mise’s discussion is at: jdx/mise#7237

  6. added a commit that references this issue on Dec 18, 2025
  7. github-actions commented on Jul 10, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 210 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  8. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jul 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions