git/list[1] front-page[2] threads[3] people[4] search[5] about
 

RE: git-send-email with GPG signed commits?

From
rsbecker@nexbridge.com <rsbecker@nexbridge.com>
Date
Oct 20, 2022, 19:40 UTC
Message-ID
<004901d8e4bb$c3338360$499a8a20$@nexbridge.com>
In-Reply-To
<20221020190117.va67kbrmvg4xxit5@meerkat.local>
On October 20, 2022 3:01 PM, Konstantin Ryabitsev wrote:
Show 14 quoted lines
>On Thu, Oct 20, 2022 at 02:31:41PM -0400, Jeff King wrote:
>> Yes, like bundles, it is losing some of the flexibility of an
>> emailed-patch workflow. I haven't played with b4's attestation too
>> much, but I think it slots into a patch workflow better. You are
>> signing the patch, not the commit, and commits which are made later
>> can refer back to the emails, which people can then verify. That's not
>> a signature on the commit, but it is a paper trail that can be followed.
>
>That is accurate -- I've looked into attempting to preserve git commit signatures via
>sent patches, precisely so they could be applied back into the tree. However, the
>consensus among developers was that this is almost never useful, and since we
>were already providing a robust paper-trail framework in the form of public-inbox
>archives, it made sense to keep patch-level attestation and git-level attestation
>separate.

As I see it, if git commit signatures become a requirement (maybe resulting from supply chain discussions), then using existing capabilities may be the most practical alternative. This would involve submitting signed commits in pull request via GitHub instead of emailing patches. I know this is not a desirable position for the git team, but it is currently available technology. In a pinch, that could satisfy the requirement. -Randall

Previous: Konstantin RyabitsevNext: Matěj Cepl
Message 10 of 13 in “git-send-email with GPG signed commits?”
  1. Matěj CeplOct 20, 2022
  2. Konstantin RyabitsevOct 20, 2022
  3. Matěj CeplOct 20, 2022
  4. Konstantin RyabitsevOct 20, 2022
  5. Jeff KingOct 20, 2022
  6. Junio C HamanoOct 20, 2022
  7. Junio C HamanoOct 20, 2022
  8. Jeff KingOct 20, 2022
  9. Konstantin RyabitsevOct 20, 2022
  10. rsbecker@nexbridge.comOct 20, 2022
  11. Matěj CeplOct 20, 2022
  12. brian m. carlsonOct 20, 2022
  13. Matěj CeplOct 21, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.