# Deprecation notice for npm PGP signatures

DevFeed: [Deprecation notice for npm PGP signatures](<https://devfeed.tech/articles/deprecation-notice-for-npm-pgp-signatures-73583.md>)

Original publisher: [Read original article](<https://github.blog/changelog/2023-03-31-deprecation-notice-for-npm-pgp-signatures>)

Author: Kevin Duck

Published: 2023-03-31T14:21:30Z

Content type: news

Language: en

Sources: [GitHub Changelog](<https://devfeed.tech/sources/github-changelog.md>)

Topics: [npm security](<https://devfeed.tech/topics/npm-security.md>), [ECDSA](<https://devfeed.tech/topics/ecdsa.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [ecdsa](<https://devfeed.tech/tags/ecdsa.md>), [keys](<https://devfeed.tech/tags/keys.md>), [npm](<https://devfeed.tech/tags/npm.md>), [packages](<https://devfeed.tech/tags/packages.md>), [pgp](<https://devfeed.tech/tags/pgp.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [registry](<https://devfeed.tech/tags/registry.md>), [verification](<https://devfeed.tech/tags/verification.md>)

## AI overview

The public npm registry moved from PGP signatures to ECDSA signatures for verification in July 2022. PGP signatures will be deprecated on April 25, 2023; from then, new packages will not be signed with PGP keys, and the public key hosted on Keybase will expire.

## Source excerpt

In July 2022 the public npm registry migrated away from the existing PGP signatures to a new ECDSA signatures for signature verification. PGP based registry signatures will be deprecated on...