Re: [RFC PATCH 4/4] Make git fetch verify signed tags
- From
Johannes Schindelin <johannes.schindelin@gmx.de>
- Date
- Nov 24, 2008, 10:44 UTC
- Message-ID
- <alpine.DEB.1.00.0811241143410.30769@pacific.mpi-cbg.de>
- In-Reply-To
- <1227497000-8684-5-git-send-email-deskinm@umich.edu>
Hi,
On Sun, 23 Nov 2008, Deskin Miller wrote:
Show 6 quoted lines
> When git fetch downloads signed tag objects, make it verify them right > then. This extends the output summary of fetch to include "(good > signature)" for valid tags and "(BAD SIGNATURE)" for invalid tags. If > the user does not have the correct key in the gpg keyring, gpg returns > 2, verify_tag_sha1 returns -2 and nothing additional is output about the > tag's validity.
This must be turned off by default, IMO. You cannot expect each and every developer to have gpg _and_ all those public keys installed.
Ciao, Dscho