Re: How to gpg signed email patches?
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Apr 14, 2025, 15:14 UTC
- Message-ID
- <xmqq34easrlo.fsf@gitster.g>
- In-Reply-To
- <20250413-dancing-acoustic-marten-cc7a7d@lemur>
Konstantin Ryabitsev <konstantin@linuxfoundation.org> writes:
Show 6 quoted lines
> On Sun, Apr 13, 2025 at 07:17:26PM +0000, Klaus Frank wrote: >> how do I get "git send-email" to send the patches gpg signed? > > You have to step back and ask what is the end-goal? Do you want > repudiation/attestation for your own patches, or do you want to be able to > verify that the patches sent to you by contributors are tamper-evident?
Excellent question. These are probably both addressed by signed e-mails, but quite different from what object-level signing (e.g. "git commit --signed") aims at.
Show 6 quoted lines
> On the kernel side of things, we've been using patatt [1], which supports PGP, > SSH, and ed25519-signing of patches via a dedicated custom header, a-la DKIM. > > [1] https://github.com/mricon/patatt/blob/main/README.rst > > -K