git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Signed tags and git repository

From
SSStephen & Linda Smith <ischis2@cox.net>
Date
Nov 25, 2015, 23:19 UTC
Message-ID
<3816223.3lD8Al3iuQ@thunderbird>

I've been following commits to the linux and git repostitories for some time. I used signed tags for projects that I'm working on.

I know that the linux and git repositories have signed tags, but I'm not able to verify them because my key isn't signed by anyone that leads back to one of the git or linux maintainers. Of course I live in a technical desert since there seems to be no one that I can find who lives in Phoenix, AZ that has a relationship to one of those two git repositories.

What have others done when they want their keys signed so they can be part of the web of trust? Does either of those two projects have a formal way of establishing these relationships?

sps
Next: Johannes Löthberg
Message 1 of 3 in “Signed tags and git repository”
  1. Stephen & Linda SmithNov 25, 2015
  2. Johannes LöthbergNov 26, 2015
  3. Stephen & Linda SmithNov 26, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.