Re: PGP signing commits

Tomaz Canabrava <[email protected]> Fri, 12 Jun 2026 08:32:26 +0200
Newsgroups gmane.comp.kde.devel.kdevelop
Message-ID <CACk01_y3TURxf1_mKKDCZ1XuP2mbzF=vS1QUq_pq7t=KL7n3qQ@mail.gmail.com>
--000000000000a45154065408a414
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Thu, Jun 11, 2026 at 10:34=E2=80=AFPM Sven Brauch <mail-ITmcY+a7/[email protected]> w=
rote:

> Hi,
>
> On 11.06.26 21:12, Martin Bednar wrote:
> > On the topic of requiring GPG signed commits, opened here:
> >
> https://invent.kde.org/kdevelop/kdevelop/-/merge_requests/896#note_151982=
2
>
> What do you effectively do with these signatures? I.e. what meaningful
> verification can you do assuming a commits is signed, in doubt, by some
> random guy nobody has ever met? At best, you can say "this and this
> contribution are by the same person", but not even the opposite is true
> since people can just say they lost their key.
>
> IMO this creates more trouble than it's worth, for new contributors but
> probably also for other people (think rebases, etc).
>

I Completely agree with Sven.
I don't see a single good reason to require gpg signed signatures,  this
will only create a higher barrier of entry for newcommers, and not just
newcommers - there are a lot of *current* developers that never bothered to
create or use a gpg signature. the tooling around it is honestly horrible.
Having the gpg signed commit is - imo - the same thing as having the
signed-off-by line.
Nothing.



> > And on a slightly related note: Anyone going to Akademy?
>
> Not this year, sorry :(
>
> Best,
> Sven
>

--000000000000a45154065408a414
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Jun 11,=
 2026 at 10:34=E2=80=AFPM Sven Brauch &lt;<a href=3D"mailto:mail@svenbrauch=
.de">mail-ITmcY+a7/[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_=
quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,=
204);padding-left:1ex">Hi,<br>
<br>
On 11.06.26 21:12, Martin Bednar wrote:<br>
&gt; On the topic of requiring GPG signed commits, opened here:<br>
&gt; <a href=3D"https://invent.kde.org/kdevelop/kdevelop/-/merge_requests/8=
96#note_1519822" rel=3D"noreferrer" target=3D"_blank">https://invent.kde.or=
g/kdevelop/kdevelop/-/merge_requests/896#note_1519822</a><br>
<br>
What do you effectively do with these signatures? I.e. what meaningful <br>
verification can you do assuming a commits is signed, in doubt, by some <br=
>
random guy nobody has ever met? At best, you can say &quot;this and this <b=
r>
contribution are by the same person&quot;, but not even the opposite is tru=
e <br>
since people can just say they lost their key.<br>
<br>
IMO this creates more trouble than it&#39;s worth, for new contributors but=
 <br>
probably also for other people (think rebases, etc).<br></blockquote><div><=
br></div><div>I Completely agree with Sven.</div><div>I don&#39;t see a sin=
gle good reason to require gpg signed signatures,=C2=A0 this will only crea=
te a higher barrier of entry for newcommers, and not just newcommers - ther=
e are a lot of *current* developers that never bothered to create or use a =
gpg signature. the tooling around it is honestly horrible.</div><div>Having=
 the gpg signed commit is - imo - the same thing as having the signed-off-b=
y line.</div><div>Nothing.</div><div><br></div><div><br></div><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli=
d rgb(204,204,204);padding-left:1ex">
<br>
&gt; And on a slightly related note: Anyone going to Akademy?<br>
<br>
Not this year, sorry :(<br>
<br>
Best,<br>
Sven<br>
</blockquote></div></div>

--000000000000a45154065408a414--