4 ms·
Yes. Here's an excerpt from their documentation on <https://docs.github.com/en/github/authenticating-to-github/managing-commit-signature-verification/about-comm
by Felk 5y ago
Yes. Here's an excerpt from their documentation on <https://docs.github.com/en/github/authenticating-to-github/managing-commit-signature-verification/about-commit-signature-verification https://docs.github.com/en/github/authenticating-to-github/m...>:
> GitHub will automatically use GPG to sign commits you make using the GitHub web interface
- chrisseaton 5y agoSays it signs the commit with its own key. I guess you have to trust GitHub.
- Felk 5y agoWell, yes. The question was whether you can sign _on GitHub_, so your private key has to be available to GitHub. You can always sign locally if you don't trust GitHub.
- drexlspivey 5y agoWhat else would they be signing with? They don’t have your key obviously
- chrisseaton 5y agoWell that was my point - I wonder why we haven't set up a system that lets me sign the merge commit. Otherwise it's a commit purported to be authored by me but when you look it's actually signed by someone else.
- ruuda 5y agoIt’s even worse, if somebody rebase-merges a pull request that you authored (thereby creating a new commit that you did not author), GitHub will show you as the author (without a separate committer, like it normally does when author and committer differ), and put “verified” next to it, which usually means that they verified that it was signed by your GPG key, but in this case, it means that the commit was created by GitHub. https://twitter.com/vmulps/status/1386717970458677250 https://twitter.com/vmulps/status/1386717970458677250