Re: PGP signing commits
Tomaz Canabrava <[email protected]> Fri, 12 Jun 2026 08:32:26 +0200
| Newsgroups | gmane.comp.kde.devel.kdevelop |
|---|---|
| Message-ID | <CACk01_y3TURxf1_mKKDCZ1XuP2mbzF=vS1QUq_pq7t=KL7n3qQ@mail.gmail.com> |
--000000000000a45154065408a414 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Thu, Jun 11, 2026 at 10:34=E2=80=AFPM Sven Brauch <mail-ITmcY+a7/[email protected]> w= rote: > Hi, > > On 11.06.26 21:12, Martin Bednar wrote: > > On the topic of requiring GPG signed commits, opened here: > > > https://invent.kde.org/kdevelop/kdevelop/-/merge_requests/896#note_151982= 2 > > What do you effectively do with these signatures? I.e. what meaningful > verification can you do assuming a commits is signed, in doubt, by some > random guy nobody has ever met? At best, you can say "this and this > contribution are by the same person", but not even the opposite is true > since people can just say they lost their key. > > IMO this creates more trouble than it's worth, for new contributors but > probably also for other people (think rebases, etc). > I Completely agree with Sven. I don't see a single good reason to require gpg signed signatures, this will only create a higher barrier of entry for newcommers, and not just newcommers - there are a lot of *current* developers that never bothered to create or use a gpg signature. the tooling around it is honestly horrible. Having the gpg signed commit is - imo - the same thing as having the signed-off-by line. Nothing. > > And on a slightly related note: Anyone going to Akademy? > > Not this year, sorry :( > > Best, > Sven > --000000000000a45154065408a414 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Jun 11,= 2026 at 10:34=E2=80=AFPM Sven Brauch <<a href=3D"mailto:mail@svenbrauch= .de">mail-ITmcY+a7/[email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_= quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,= 204);padding-left:1ex">Hi,<br> <br> On 11.06.26 21:12, Martin Bednar wrote:<br> > On the topic of requiring GPG signed commits, opened here:<br> > <a href=3D"https://invent.kde.org/kdevelop/kdevelop/-/merge_requests/8= 96#note_1519822" rel=3D"noreferrer" target=3D"_blank">https://invent.kde.or= g/kdevelop/kdevelop/-/merge_requests/896#note_1519822</a><br> <br> What do you effectively do with these signatures? I.e. what meaningful <br> verification can you do assuming a commits is signed, in doubt, by some <br= > random guy nobody has ever met? At best, you can say "this and this <b= r> contribution are by the same person", but not even the opposite is tru= e <br> since people can just say they lost their key.<br> <br> IMO this creates more trouble than it's worth, for new contributors but= <br> probably also for other people (think rebases, etc).<br></blockquote><div><= br></div><div>I Completely agree with Sven.</div><div>I don't see a sin= gle good reason to require gpg signed signatures,=C2=A0 this will only crea= te a higher barrier of entry for newcommers, and not just newcommers - ther= e are a lot of *current* developers that never bothered to create or use a = gpg signature. the tooling around it is honestly horrible.</div><div>Having= the gpg signed commit is - imo - the same thing as having the signed-off-b= y line.</div><div>Nothing.</div><div><br></div><div><br></div><blockquote c= lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli= d rgb(204,204,204);padding-left:1ex"> <br> > And on a slightly related note: Anyone going to Akademy?<br> <br> Not this year, sorry :(<br> <br> Best,<br> Sven<br> </blockquote></div></div> --000000000000a45154065408a414--