git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Would it make sense to add a commit.signOff config?

From
Johannes Sixt <j6t@kdbg.org>
Date
Dec 16, 2025, 07:15 UTC
Message-ID
<706588fa-97f7-40b1-86c9-8e5c944c173a@kdbg.org>
In-Reply-To
<CABPp-BGCwjTBEi4wkg=065QofiO9ZL+9XVCCcTiHriXqgH1Szw@mail.gmail.com>
Am 16.12.25 um 01:17 schrieb Elijah Newren:
Show 37 quoted lines
> On Sun, Dec 14, 2025 at 6:00 PM Junio C Hamano <gitster@pobox.com> wrote:
>> --- c/Documentation/gitfaq.adoc
>> +++ w/Documentation/gitfaq.adoc
>> @@ -83,6 +83,21 @@ Windows would be the configuration `"C:\Program Files\Vim\gvim.exe" --nofork`,
>>  which quotes the filename with spaces and specifies the `--nofork` option to
>>  avoid backgrounding the process.
>>
>> +[[sign-off]]
>> +Why not have `commit.signoff` and other configuration variables?::
>> +       As it makes it harder to argue against one who tells the court
>> +       "the log message of the commit ends with a Signed-off-by
>> +       trailer by person X, but it is very plausible that it was done
>> +       by inertia without person X really intending to certify what
>> +       DCO says, hence the Signed-off-by trailer is meaningless", if
>> +       we add more publicized ways to add sign-off automatically, Git
>> +       does not (and will not) have a configuration variable to
>> +       enable the `--signoff` command line option it by default.
> 
> This feels kind of hard to parse for me.  Maybe it's just the lack of
> sentence breaks, particularly near the end.  Let me take a stab at an
> alternative:
> 
> Git intentionally does not (and will not) provide a configuration variable,
> such as `commit.signoff`, to automatically add `--signoff` by default.
> The reason is to protect the legal and intentional significance of a sign-off.
> If there were more automated and widely publicized ways for sign-offs to be
> appended, it would become easier for someone to argue later that a
> "Signed-off-by" trailer was just added out of habit or by automation,
> without the committer's full awareness or intent to certify their agreement
> with the Developer Certificate of Origin (DCO) or a similar statement.
> This would weaken the sign-off’s value and could undermine its credibility
> in legal or contractual situations. To uphold the integrity of a sign-off,
> Git only adds it when explicitly requested, rather than through automatic
> configuration settings.
> 
> Maybe the last sentence or two are a bit redundant and could be
> stricken.  Anyway, thoughts?
This is much easier to read. I'd shorten the last two sentences to

This could undermine the sign-off’s credibility in legal or contractual situations.

-- Hannes
Previous: Johannes SixtNext: Junio C Hamano
Message 12 of 20 in “Would it make sense to add a commit.signOff config?”
  1. Stefan HallerDec 14, 2025
  2. Carlo Marcelo Arenas BelónDec 14, 2025
  3. Junio C HamanoDec 14, 2025
  4. Collin FunkDec 14, 2025
  5. brian m. carlsonDec 15, 2025
  6. Junio C HamanoDec 15, 2025
  7. brian m. carlsonDec 15, 2025
  8. Junio C HamanoDec 16, 2025
  9. Elijah NewrenDec 16, 2025
  10. Junio C HamanoDec 16, 2025
  11. Johannes SixtDec 16, 2025
  12. Johannes SixtDec 16, 2025
  13. commit: document that $command.signoff will not be addedJunio C Hamano, Dec 16, 2025
  14. Elijah NewrenDec 16, 2025
  15. Junio C HamanoDec 17, 2025
  16. Elijah NewrenDec 17, 2025
  17. Johannes SixtDec 17, 2025
  18. Junio C HamanoDec 17, 2025
  19. Kristoffer HaugsbakkDec 19, 2025
  20. Junio C HamanoDec 19, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.