5 ms·
Signing commits is such a pain to set up. I'm convinced its such a boring area with so little profit that no one has spent enough time to make it more straight
by AlwaysRock 3y ago
Signing commits is such a pain to set up. I'm convinced its such a boring area with so little profit that no one has spent enough time to make it more straight forward.
- sitzkrieg 3y agoyou can sign w ssh key w 2 git configs set. im not sure this qualifies as pain
- cryptonector 3y agoIt's meaningless unless your keys are known to others to speak for you. I.e., you have to participate in the PGP trust mesh, and that is what is a pain.
- AlwaysRock 3y agoYup. This.
- woodrowbarlow 3y agoisn't this what keybase is for?
- arccy 3y agoor github.com/<username>.keys
- Arnavion 3y agohttps://datatracker.ietf.org/doc/draft-koch-openpgp-webkey-service/17/ https://datatracker.ietf.org/doc/draft-koch-openpgp-webkey-s... Serve the key at a certain URL from a webserver on your email domain. Clients that trust the domain can trust the key that it serves.
- influx 3y ago1Password makes it easy to do with ssh keys and biometrics. It’s actually pretty slick.
- g4zj 3y agoI tend to agree with Linus Torvalds' statement about signing tags rather than commits. https://web.archive.org/web/20201111174438/http://git.661346.n2.nabble.com/GPG-signing-for-git-commit-td2582986.html#a2583316 https://web.archive.org/web/20201111174438/http://git.661346...
- Arnavion 3y agoWhat's hard about it? You just define `user.signingkey = $key_id` and `commit.gpgsign = true` in `~/.config/git/config` once and be done with it. Or only the first one if you want to choose what you sign instead of signing everything. Or are you talking about setting up GPG in general?