4 ms·
Does anybody know if this only verifies _new_ commits? I've been signing my commits with my SSH key for a while, but older commits still show as unverified in t
by grncdr 4y ago
Does anybody know if this only verifies _new_ commits? I've been signing my commits with my SSH key for a while, but older commits still show as unverified in the web UI. They show the hash of the public key the commit was signed with, which matches a public key associated with my account in the account settings, but the commit still says "Unverified".
Example: https://github.com/grncdr/dev-mode/commit/06376070aff042e9d5b9114994335e5205f0a0f6 https://github.com/grncdr/dev-mode/commit/06376070aff042e9d5...
- tylerhou 4y agoMy guess is that they may have forgotten to backfill old data (because probably whether a commit is verified is not computed on the fly), but I don't see why it can't apply retroactively. Maybe try removing and adding the public key from your account? That might trigger the system to scan all your commits and re-verify.
- arccy 4y agoAll my old commits show as verified now
- Reitet00 4y agoYou need to re-add your SSH key and there's a new key type select box that has "signing" option. The old keys are only good for auth.
- grncdr 4y agoThis was it, thanks for the pointer!
- caleb_thompson 4y agoYou'll need to re-upload your public SSH key as a signing key for the signatures to be shown as verified. https://calebhearth.com/sign-git-with-ssh#github https://calebhearth.com/sign-git-with-ssh#github
- grncdr 4y agoThis was it, thanks for the pointer!