Re: PGP signing commits

Jarmo Tiitto <[email protected]> Sun, 14 Jun 2026 18:42:44 +0300
Newsgroups gmane.comp.kde.devel.kdevelop
Message-ID <CAH9JF8saKaEuQ1YqXuJzF2GLqCu7mhP2kGk5j-xTqGcsk=r67g@mail.gmail.com>
--0000000000004a6c900654389013
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

> IMO this creates more trouble than it's worth, for new contributors but
probably also for other people (think rebases, etc).

> I don't see a single good reason to require gpg signed signatures,  this
will only create a higher barrier of entry for newcommers, and not just
newcommers - there are a lot of *current* developers that never bothered to
create or use a gpg signature. the tooling around it is honestly horrible

I was unaware of the the general stance when I requested enabling gpg
signed commits. I mostly though of it as "a nice to have" thing that would
improve trust.

I have been using GPG signing from around 2023-2024 to this day, and I
agree it is a hurdle to setup. In practice the only hurdle for me is that I
need to open my keyring once a day and after this the signing is automatic,
including rebases.

I do think contributors who have developer rights (can merge to master)
should eventually enable it. One off new contributors don't need to enable
it, though here the signing would be most beneficial.

Looks like I'll need to soften my stance on this, and we can keep the GPG
signing optional.

Thanks for the discussion.

(sent from gmail)


la 13.6.2026 klo 10.35 Tomaz Canabrava ([email protected])
kirjoitti:

>
>
> On Thu, Jun 11, 2026 at 10:34=E2=80=AFPM Sven Brauch <mail-ITmcY+a7/[email protected]>=
 wrote:
>
>> Hi,
>>
>> On 11.06.26 21:12, Martin Bednar wrote:
>> > On the topic of requiring GPG signed commits, opened here:
>> >
>> https://invent.kde.org/kdevelop/kdevelop/-/merge_requests/896#note_15198=
22
>>
>> What do you effectively do with these signatures? I.e. what meaningful
>> verification can you do assuming a commits is signed, in doubt, by some
>> random guy nobody has ever met? At best, you can say "this and this
>> contribution are by the same person", but not even the opposite is true
>> since people can just say they lost their key.
>>
>> IMO this creates more trouble than it's worth, for new contributors but
>> probably also for other people (think rebases, etc).
>>
>
> I Completely agree with Sven.
> I don't see a single good reason to require gpg signed signatures,  this
> will only create a higher barrier of entry for newcommers, and not just
> newcommers - there are a lot of *current* developers that never bothered =
to
> create or use a gpg signature. the tooling around it is honestly horrible=
.
> Having the gpg signed commit is - imo - the same thing as having the
> signed-off-by line.
> Nothing.
>
>
>
>> > And on a slightly related note: Anyone going to Akademy?
>>
>> Not this year, sorry :(
>>
>> Best,
>> Sven
>>
>

--0000000000004a6c900654389013
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>&gt; IMO this creates more trouble than it&#39;s wort=
h, for new contributors but probably also for other people (think rebases, =
etc).</div><div><br></div><div>&gt;=C2=A0I don&#39;t see a single good reas=
on to require gpg signed signatures,=C2=A0 this
 will only create a higher barrier of entry for newcommers, and not just
 newcommers - there are a lot of *current* developers that never=20
bothered to create or use a gpg signature. the tooling around it is=20
honestly horrible</div><div><br></div>I was unaware of the the general stan=
ce when I requested enabling gpg signed commits. I mostly though of it as &=
quot;a nice to have&quot; thing that would improve trust.<br><br>I have bee=
n using GPG signing from around 2023-2024 to this day, and I agree it is a =
hurdle to setup. In practice the only hurdle for me is that I need to open =
my keyring once a day and after this the signing is automatic, including re=
bases.<br><br>I do think contributors who have developer rights (can merge =
to master) should eventually enable it. One off new contributors don&#39;t =
need to enable it, though here the signing would be most beneficial.<br><br=
>Looks like I&#39;ll need to soften my stance on this, and we can keep the =
GPG signing optional.<br><br>Thanks for the discussion.<div><br></div><div>=
(sent from gmail)</div><div><span class=3D"im"><br></span></div></div><br><=
div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"g=
mail_attr">la 13.6.2026 klo 10.35 Tomaz Canabrava (<a href=3D"mailto:tomaz.=
[email protected]">[email protected]</a>) kirjoitti:<br></div><bl=
ockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-lef=
t:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div dir=3D=
"ltr"><br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gm=
ail_attr">On Thu, Jun 11, 2026 at 10:34=E2=80=AFPM Sven Brauch &lt;<a href=
=3D"mailto:mail-ITmcY+a7/[email protected]" target=3D"_blank">mail-ITmcY+a7/[email protected]</a>&gt;=
 wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px =
0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi,<br>
<br>
On 11.06.26 21:12, Martin Bednar wrote:<br>
&gt; On the topic of requiring GPG signed commits, opened here:<br>
&gt; <a href=3D"https://invent.kde.org/kdevelop/kdevelop/-/merge_requests/8=
96#note_1519822" rel=3D"noreferrer" target=3D"_blank">https://invent.kde.or=
g/kdevelop/kdevelop/-/merge_requests/896#note_1519822</a><br>
<br>
What do you effectively do with these signatures? I.e. what meaningful <br>
verification can you do assuming a commits is signed, in doubt, by some <br=
>
random guy nobody has ever met? At best, you can say &quot;this and this <b=
r>
contribution are by the same person&quot;, but not even the opposite is tru=
e <br>
since people can just say they lost their key.<br>
<br>
IMO this creates more trouble than it&#39;s worth, for new contributors but=
 <br>
probably also for other people (think rebases, etc).<br></blockquote><div><=
br></div><div>I Completely agree with Sven.</div><div>I don&#39;t see a sin=
gle good reason to require gpg signed signatures,=C2=A0 this will only crea=
te a higher barrier of entry for newcommers, and not just newcommers - ther=
e are a lot of *current* developers that never bothered to create or use a =
gpg signature. the tooling around it is honestly horrible.</div><div>Having=
 the gpg signed commit is - imo - the same thing as having the signed-off-b=
y line.</div><div>Nothing.</div><div><br></div><div><br></div><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli=
d rgb(204,204,204);padding-left:1ex">
<br>
&gt; And on a slightly related note: Anyone going to Akademy?<br>
<br>
Not this year, sorry :(<br>
<br>
Best,<br>
Sven<br>
</blockquote></div></div>
</blockquote></div>

--0000000000004a6c900654389013--