git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 4/4] Make git fetch verify signed tags

From
Deskin Miller <deskinm@umich.edu>
Date
Nov 28, 2008, 00:19 UTC
Message-ID
<20081128001901.GC29662@euler>
In-Reply-To
<alpine.DEB.1.00.0811241143410.30769@pacific.mpi-cbg.de>
On Mon, Nov 24, 2008 at 11:44:40AM +0100, Johannes Schindelin wrote:
Show 13 quoted lines
> Hi,
> 
> On Sun, 23 Nov 2008, Deskin Miller wrote:
> 
> > When git fetch downloads signed tag objects, make it verify them right 
> > then.  This extends the output summary of fetch to include "(good 
> > signature)" for valid tags and "(BAD SIGNATURE)" for invalid tags.  If 
> > the user does not have the correct key in the gpg keyring, gpg returns 
> > 2, verify_tag_sha1 returns -2 and nothing additional is output about the 
> > tag's validity.
> 
> This must be turned off by default, IMO.  You cannot expect each and every 
> developer to have gpg _and_ all those public keys installed.

Adding a configuration variable to control this makes sense, and is on my TODO list for v2 (core.autoVerifyTags?). However, I don't see a compelling reason to make it off by default, as if gpg isn't found, or a particular public key isn't in the keyring, the output is no different from what fetch prints now.

Deskin Miller
Previous: Johannes SchindelinNext: Johannes Schindelin
Message 7 of 16 in “Teach git fetch to verify signed tags automatically”
  1. 0/4 Teach git fetch to verify signed tags automaticallyDeskin Miller, Nov 24, 2008
  2. 1/4 Refactor builtin-verify-tag.cDeskin Miller, Nov 24, 2008
  3. 2/4 verify-tag.c: ignore SIGPIPE around gpg invocationDeskin Miller, Nov 24, 2008
  4. 3/4 verify-tag.c: suppress gpg output if askedDeskin Miller, Nov 24, 2008
  5. 4/4 Make git fetch verify signed tagsDeskin Miller, Nov 24, 2008
  6. Johannes SchindelinNov 24, 2008
  7. Deskin MillerNov 28, 2008
  8. Johannes SchindelinNov 24, 2008
  9. Deskin MillerNov 28, 2008
  10. Junio C HamanoNov 24, 2008
  11. Junio C HamanoNov 24, 2008
  12. Deskin MillerNov 28, 2008
  13. Johannes SchindelinNov 28, 2008
  14. Johannes SchindelinNov 24, 2008
  15. Deskin MillerNov 28, 2008
  16. Junio C HamanoNov 28, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.