git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Teams of people using signed commits...

From
Fredrik Gustafsson <iveqy@iveqy.com>
Date
Jun 14, 2013, 22:06 UTC
Message-ID
<20130614220627.GA371@paksenarrion.iveqy.com>
In-Reply-To
<CABQymNKuwiOz-MQuM12fWSgBvBsBrykNYBqPBxCuSuxAC5cZZw@mail.gmail.com>
On Fri, Jun 14, 2013 at 12:02:01PM -0700, Eric Fleischman wrote:
Show 14 quoted lines
> We think we know how to deal with signed commits & auto-reject such
> commits at build time, as well as clean up. But we're worried that
> folks won't sign on the way in accidentally. We don't know of a good
> way to force the team to always sign commits yet, especially as they
> get new machines and what hav eyou.
> 
> Is there a way to add something to the repo config to force, or at
> least default, this?
> We considered forking git and forcing this on the team, forcing them
> to sign for our repos. But we'd love to avoid this sort of
> heavy-handed approach.
> 
> Thx!
> Eric

Hi, I might miss something here, but couldn't you just write a pre-commit hook on the client side to help the developers remember and a post-receive hook on the server side to actually enforce this?

With that said, I'm a bit skeptical about enforcing ways to use software. It usually hide real social problems instead. For example, if your developers doesn't understand the value in always signing their commits, can you trust that they protect their gpg-key well enough?

-- 
Med vänliga hälsningar
Fredrik Gustafsson

tel: 0733-608274
e-post: iveqy@iveqy.com
Previous: Magnus Bäck
Message 3 of 3 in “Teams of people using signed commits...”
  1. Eric FleischmanJun 14, 2013
  2. Magnus BäckJun 14, 2013
  3. Fredrik GustafssonJun 14, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.