3 ms·
That is great news! I hope they will also go the next tiny steps soon: 1) as another commenter already pointed out, I would really like to see an "unverified"
by sarnowski 11y ago
That is great news! I hope they will also go the next tiny steps soon:
1) as another commenter already pointed out, I would really like to see an "unverified" badge instead of the "verified" to make GPG signing the default; everyone should really be aware that all commit metadata like author and committer are completely voluntary and you can lie as you want.
2) Please, add another merge restriction that only allows commit pushes/merges-to-master with GPG signatures. This allows me to fully verify future git repositories.
- matt_wulfeck 11y agoThat would require the --sign flag with every commit would it not? That sounds like a pain. I would like git to automatically sign my commits if that were the case.
- sarnowski 11y agoYou can set up the --sign flag in your local gitconfig. git config --global user.signingkey $GPGKEY git config --global commit.gpgsign true In general, since you definitely do not want to upload your key material to GitHub, you won't be able to use the pull request merge button and the new squash button. This means, your pull requests need to be fast-forwardable, else you cannot merge (as this merge would be unsigned). Also, instead of using the squash button, you would need to squash the commits on your local machine and push the newly signed squashed commit again. It comes as a cost but it also leverages the decentralized nature of git: you can do everything locally and sign locally so you do not need to trust someone else.
- joeyh 11y agogit can sign merges.
- sgarman 11y agoRight, but GitHub can't unless it has your private key which it probably should't(if it's password protected) but that's a discussion for another time. Many people use the feature on GitHub to manage their projects like the merge button.
- nickik 10y agoTheir are two solutions. 1. Develop an browser API that can request GPG operations. Something like they are doing now with U2F 2. Github could pop up a script that can be copy pasted into the command line. The same way Keybase does it when you don't upload your private key
- orangeshark 11y agoYou can configure git to sign commits by default with commit.gpgSign https://git-scm.com/docs/git-config https://git-scm.com/docs/git-config
- deleted 11y ago[deleted]
- cyphar 11y agoGPG signing every commit has dubious benefits. You have to rebase your entire history if your GPG key is compromised. It also increases the footprint of the repo, and having signatures for more than HEAD is redundant (if the repo state is valid, then the DAG has been verified already). The best thing to do is to sign tags, IMO.