Re: [Tagging Commits] feedback / discussion request
- From
Michael J Gruber <git@drmicha.warpmail.net>
- Date
- May 4, 2011, 09:21 UTC
- Message-ID
- <4DC11A8F.5020408@drmicha.warpmail.net>
- In-Reply-To
- <BANLkTimTmkufMnY5dJtDD6BWxs=vsDTygA@mail.gmail.com>
Sverre Rabbelier venit, vidit, dixit 04.05.2011 01:49:
Show 9 quoted lines
> Heya, > > On Wed, May 4, 2011 at 01:36, Richard Peterson <richard@rcpeterson.com> wrote: >> Thank you, and please give feedback. I'm no git pro - just a guy with an >> idea. Based on your feedback, Eric and I will steer our implementation. > > Have you looked at git notes? They seem relevant. You could use them > to sign commits after the fact, and by multiple people, etc. >
Exactly. Sign and store sig in refs/notes/sigs:
git rev-parse <commit> | gpg -sa | git notes --ref=sigs append -F- <commit>
Verify:
git notes --ref=sigs show <commit> | gpg
You can sign any object (blob, tree...) that way, of course.
Everything else (meaning of this sig, just like the meaning of a signed tag or a s-o-b line) is a matter of project policy.
Michael