Re: PGP signing commits

Martin Bednar <martin-bVyCAMn5I1PtwjQa/[email protected]> Fri, 12 Jun 2026 14:24:21 +0200
Newsgroups gmane.comp.kde.devel.kdevelop
Message-ID <[email protected]>
--nextPartuAZKSiYlSsye3qQnTXg56w
Content-Transfer-Encoding: 7Bit
Content-Type: text/plain; charset="utf-8"; protected-headers="v1"
From: Martin Bednar <martin-bVyCAMn5I1PtwjQa/[email protected]>
To: [email protected], Sven Brauch <mail-ITmcY+a7/[email protected]>
Subject: Re: PGP signing commits
Date: Fri, 12 Jun 2026 14:24:21 +0200
Message-ID: <EJk0vSqxT06zVRU4zvjX7A-bVyCAMn5I1PtwjQa/[email protected]>
In-Reply-To: <ab3d83dc-e030-48fb-9628-e869e5c45b5d-ITmcY+a7/[email protected]>
MIME-Version: 1.0

Hi,

On Thursday, 11 June 2026 22:34:27 Central European Summer Time Sven Brauch 
wrote:
> 
> What do you effectively do with these signatures? I.e. what meaningful 
> verification can you do assuming a commits is signed, in doubt, by some 
> random guy nobody has ever met? At best, you can say "this and this 
> contribution are by the same person", but not even the opposite is true 
> since people can just say they lost their key.

The Linux kernel uses PGP signing of commits as a failsafe in case 
infrastructure gets compromised.
https://www.kernel.org/doc/html/next/process/maintainer-pgp-guide.html

That actually is something signed commits/tags can do. I don't think that 
requires every commit to be signed.

Regards,

Martin
--nextPartuAZKSiYlSsye3qQnTXg56w
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part.
Content-Transfer-Encoding: 7Bit

-----BEGIN PGP SIGNATURE-----

iJEEABYKADkWIQSQahp3QLKdvHTT9rcGyo/AjsPylgUCaiv6dhsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDIACgkQBsqPwI7D8pYikQEAoY3RDKl6ZisusyiOFnxZ
tTqdvdh7AxAeaapFncNtgXcBAKPD8K5wYgqLSfpBclikjui3ne2TZEWPSC/v/hp/
ZbkH
=0cn0
-----END PGP SIGNATURE-----

--nextPartuAZKSiYlSsye3qQnTXg56w--