RE: Lack of detached signatures
- From
- Olsen, Alan R <alan.r.olsen@intel.com>
- Date
- Sep 28, 2011, 04:17 UTC
- Message-ID
- <4B2793BF110AAB47AB0EE7B90897038516F63A7C@ORSMSX101.amr.corp.intel.com>
- In-Reply-To
- <CAMOZ1Bs2HW6e3V6sayVSm0NhC=0e5129ZR8YSGuZPnJw9H9TEA@mail.gmail.com>
[Sorry for the top posting. Outlook is evil.]
Detached signatures are created with gpg, not git.
What I would like to see in git would be signed commits. I have looked at what it would take to make it work, but I don't have all the details worked out. (Certain merges and cherry-picks would not work very well.)
-----Original Message----- From: git-owner@vger.kernel.org [mailto:git-owner@vger.kernel.org] On Behalf Of Michael Witten Sent: Tuesday, September 27, 2011 5:08 PM To: Junio C Hamano Cc: Joseph Parmelee; git@vger.kernel.org Subject: Re: Lack of detached signatures
On Wed, Sep 28, 2011 at 00:03, Junio C Hamano <gitster@pobox.com> wrote:
Show 8 quoted lines
> Joseph Parmelee <jparmele@wildbear.com> writes: > >> Under the present circumstances, and particularly considering the >> sensitivity of the git code itself, I would suggest that you implement >> signed detached digital signatures on all release tarballs. > > Well, signed tags are essentially detached signatures. People can verify > tarballs against them if they wanted to, although it is a bit cumbersome.
Aren't tarballs used to get git on machines that don't yet have git? -- To unsubscribe from this list: send the line "unsubscribe git" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html