git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Request for Documentation] Differentiate signed (commits/tags/pushes)

From
Jakub Narębski <jnareb@gmail.com>
Date
Mar 6, 2017, 23:59 UTC
Message-ID
<47ad8b6d-0a65-2f8c-dcc5-49a8a8d5ab2a@gmail.com>
In-Reply-To
<xmqqshmqm4ur.fsf@junio-linux.mtv.corp.google.com>
W dniu 06.03.2017 o 23:13, Junio C Hamano pisze:
> Stefan Beller <sbeller@google.com> writes:
> 
>> What is the difference between signed commits and tags?
>> (Not from a technical perspective, but for the end user)
[...]
Show 16 quoted lines
>> Off list I was told gpg-signed commits are a "checkbox feature",
>> i.e. no real world workflow would actually use it. (That's a bold
>> statement, someone has to use it as there was enough interest
>> to implement it, no?)
> 
> I'd agree with that "checkbox" description, except that you need to
> remember that a project can enforce _any_ workflow to its developer,
> even if it does not make much sense, and at that point, the workflow
> would become a real-world workflow.  The word "real world workflow"
> does not make any assurance if that workflow is sensible.
> 
> Historically, "tag -s" came a lot earlier.  When a project for
> whatever reason wants signature for each and every commit so that
> they somehow can feel good, without "commit -s", it would have made
> us unnecessary work to scale tag namespace only because there will
> be tons of pointless tags.  "commit -s" was a remedy for that.

Also from what I remember signed commits came before mergetags, that is the result of merging a signed tag (storing the signature of one of parents of the merge commit to not pollute tag namespace).

And this workflow, from what I know, is quite useful.
-- 
Jakub Narębski
 
Previous: Stefan BellerNext: Junio C Hamano
Message 6 of 13 in “[Request for Documentation] Differentiate signed (commits/tags/pushes)”
  1. Stefan BellerMar 6, 2017
  2. Junio C HamanoMar 6, 2017
  3. Stefan BellerMar 6, 2017
  4. Junio C HamanoMar 7, 2017
  5. Stefan BellerMar 7, 2017
  6. Jakub NarębskiMar 6, 2017
  7. Junio C HamanoMar 7, 2017
  8. Junio C HamanoMar 6, 2017
  9. Jeff KingMar 7, 2017
  10. Tom JonesMar 7, 2017
  11. Stefan BellerMar 7, 2017
  12. Jeff KingMar 8, 2017
  13. Matthieu MoyMar 7, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.