git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Commit signing

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Jan 15, 2007, 10:59 UTC
Message-ID
<Pine.LNX.4.63.0701151149030.22628@wbgn013.biozentrum.uni-wuerzburg.de>
In-Reply-To
<200701151042.12753.andyparkins@gmail.com>
Hi,
On Mon, 15 Jan 2007, Andy Parkins wrote:
Show 7 quoted lines
> As an example of why this would be useful: let's say we have a developer 
> committing to a maintainer repository who then merges those changes into 
> mainline and pushes up to the central repository (like what happens with 
> Linux).  The commits to the central repository are made using the ssh 
> login of the maintainer, but they are adding commits by someone else.  
> What if that someone else isn't allowed to commit to the central?  With 
> signed commits the option is available to exclude them.

IMHO the thinko is the old CVS one. With git we _discourage_ a central repository where everybody pushes into. We _encourage_ local repositories, which are controlled by _one_ person.

If you need a central repository with one "official" version, then designate a release officer. This officer is responsible to keep the repository clean. And I _guarantee_ you that she can tell where she pulled bad commits from: it is written down in the "Merge from" message.

And BTW you have no option to exclude unsigned commits when pushing to a repository. It is either all in or all out.

Ciao, Dscho

Previous: Martin LanghoffNext: Jakub Narebski
Message 19 of 21 in “Commit signing”
  1. Andy ParkinsJan 15, 2007
  2. Matthias KestenholzJan 15, 2007
  3. Shawn O. PearceJan 15, 2007
  4. Shawn O. PearceJan 15, 2007
  5. Johannes SchindelinJan 15, 2007
  6. Daniel BarkalowJan 15, 2007
  7. Johannes SchindelinJan 15, 2007
  8. Shawn O. PearceJan 15, 2007
  9. Karl HasselströmJan 15, 2007
  10. Andy ParkinsJan 15, 2007
  11. Shawn O. PearceJan 15, 2007
  12. Johannes SchindelinJan 15, 2007
  13. Andy ParkinsJan 15, 2007
  14. Johannes SchindelinJan 15, 2007
  15. Andy ParkinsJan 15, 2007
  16. Martin LanghoffJan 15, 2007
  17. Andy ParkinsJan 15, 2007
  18. Martin LanghoffJan 15, 2007
  19. Johannes SchindelinJan 15, 2007
  20. Jakub NarebskiJan 15, 2007
  21. Jeff KingJan 15, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.