git/list[1] front-page[2] threads[3] people[4] search[5] about
 

How to Verify Git GPG Signed Downloads?

From
Brooke Kuhlmann <brooke@alchemists.io>
Date
Jan 24, 2021, 16:49 UTC
Message-ID
<B6DFB74D-A722-4DBD-A4B2-562604B21CCB@alchemists.io>
Hello, I'm trying to figure out how to obtain the public key used to encrypt the Git file downloads. I put together a gist that explains the problem and question in detail here:
https://gist.github.com/bkuhlmann/684b74d25d83d52df8d0caeb6219aa15
If anyone has any advice on how to make this possible, it would be greatly appreciated.

Thanks, Brooke

Next: Jason Pyeron
Message 1 of 5 in “How to Verify Git GPG Signed Downloads?”
  1. Brooke KuhlmannJan 24, 2021
  2. Jason PyeronJan 24, 2021
  3. brian m. carlsonJan 24, 2021
  4. Jason PyeronJan 24, 2021
  5. Junio C HamanoJan 25, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.