hull keyring add
Synopsis
hull keyring add installs a PGP public key into hull’s keyring so that its
signer becomes trusted for --verify operations. You point it at a key file;
hull validates the file is a real public key and copies it into
~/.config/hull/keyring/.
When to use it
- To trust a new package signer — a maintainer’s published key or a CI-bot key — before you verify or install their signed packages.
- After a key rotation, to install the replacement key (use
--forceto overwrite the old file).
What happens
- Reads the key file at
<key-file>. If it cannot be read, the command errors. - Validates that the file is a recognisable PGP public key (ASCII-armoured or binary). Anything else is rejected, so junk never enters the trust store.
- Copies it into
~/.config/hull/keyring/under its original filename. A filename already in the keyring is an error unless you pass--force. - Prints
Installed key <filename> (<fingerprint>).
Usage
hull keyring add <key-file> [flags]
Flags
| Flag | Cause → effect |
|---|---|
--force |
Overwrite a key already installed under the same filename; without it, a name collision is an error. |
Also inherits the global flags.
Worked example
INPUT — a signer’s public key exported to jane.pub:
gpg --export --armor jane@example.com > jane.pub
Add it to the keyring:
hull keyring add ./jane.pub
OUTPUT — hull confirms the install and prints the fingerprint:
Installed key jane.pub (3AA5C34371567BD2)
Confirm it is trusted — the key now appears in the listing:
hull keyring list
FINGERPRINT FILE
3AA5C34371567BD2 jane.pub
hull will now accept packages signed by this key when you pass --verify.
See also
keyring— the parent commandkeyring list— confirm the key installedkeyring remove— revoke the key laterpackage verify— verify a package against the keyring