4 ms·
You can set up the --sign flag in your local gitconfig. git config --global user.signingkey $GPGKEY git config --global commit.gpgsign true In general
by sarnowski 11y ago
You can set up the --sign flag in your local gitconfig.
git config --global user.signingkey $GPGKEY
git config --global commit.gpgsign true
In general, since you definitely do not want to upload your key material to GitHub, you won't be able to use the pull request merge button and the new squash button. This means, your pull requests need to be fast-forwardable, else you cannot merge (as this merge would be unsigned). Also, instead of using the squash button, you would need to squash the commits on your local machine and push the newly signed squashed commit again. It comes as a cost but it also leverages the decentralized nature of git: you can do everything locally and sign locally so you do not need to trust someone else.
- joeyh 11y agogit can sign merges.
- sgarman 11y agoRight, but GitHub can't unless it has your private key which it probably should't(if it's password protected) but that's a discussion for another time. Many people use the feature on GitHub to manage their projects like the merge button.
- nickik 11y agoTheir are two solutions. 1. Develop an browser API that can request GPG operations. Something like they are doing now with U2F 2. Github could pop up a script that can be copy pasted into the command line. The same way Keybase does it when you don't upload your private key