Re: PGP signing commits
Martin Bednar <martin-bVyCAMn5I1PtwjQa/[email protected]> Fri, 12 Jun 2026 14:24:21 +0200
| Newsgroups | gmane.comp.kde.devel.kdevelop |
|---|---|
| Message-ID | <[email protected]> |
--nextPartuAZKSiYlSsye3qQnTXg56w Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="utf-8"; protected-headers="v1" From: Martin Bednar <martin-bVyCAMn5I1PtwjQa/[email protected]> To: [email protected], Sven Brauch <mail-ITmcY+a7/[email protected]> Subject: Re: PGP signing commits Date: Fri, 12 Jun 2026 14:24:21 +0200 Message-ID: <EJk0vSqxT06zVRU4zvjX7A-bVyCAMn5I1PtwjQa/[email protected]> In-Reply-To: <ab3d83dc-e030-48fb-9628-e869e5c45b5d-ITmcY+a7/[email protected]> MIME-Version: 1.0 Hi, On Thursday, 11 June 2026 22:34:27 Central European Summer Time Sven Brauch wrote: > > What do you effectively do with these signatures? I.e. what meaningful > verification can you do assuming a commits is signed, in doubt, by some > random guy nobody has ever met? At best, you can say "this and this > contribution are by the same person", but not even the opposite is true > since people can just say they lost their key. The Linux kernel uses PGP signing of commits as a failsafe in case infrastructure gets compromised. https://www.kernel.org/doc/html/next/process/maintainer-pgp-guide.html That actually is something signed commits/tags can do. I don't think that requires every commit to be signed. Regards, Martin --nextPartuAZKSiYlSsye3qQnTXg56w Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part. Content-Transfer-Encoding: 7Bit -----BEGIN PGP SIGNATURE----- iJEEABYKADkWIQSQahp3QLKdvHTT9rcGyo/AjsPylgUCaiv6dhsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDIACgkQBsqPwI7D8pYikQEAoY3RDKl6ZisusyiOFnxZ tTqdvdh7AxAeaapFncNtgXcBAKPD8K5wYgqLSfpBclikjui3ne2TZEWPSC/v/hp/ ZbkH =0cn0 -----END PGP SIGNATURE----- --nextPartuAZKSiYlSsye3qQnTXg56w--