5 ms·
People don't get the security concepts. Probably, just a lot of people wanted signed commits because they somehow "better", but couldn't get PGP to work. But t
by wolletd 3y ago
People don't get the security concepts. Probably, just a lot of people wanted signed commits because they somehow "better", but couldn't get PGP to work.
But they use SSH keys to push to GitHub anyway, so someone added the option to use SSH keys to sign Git commits. Now everyone can have a green "Verified" symbol on their commits.
It's worth less, but it looks better!
- thrwwycbr 3y agoChecklist security in a nutshell. Does it have a checkmark? Yes? Must be secure then.