git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: How to gpg signed email patches?

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 14, 2025, 15:14 UTC
Message-ID
<xmqq34easrlo.fsf@gitster.g>
In-Reply-To
<20250413-dancing-acoustic-marten-cc7a7d@lemur>
Konstantin Ryabitsev <konstantin@linuxfoundation.org> writes:
Show 6 quoted lines
> On Sun, Apr 13, 2025 at 07:17:26PM +0000, Klaus Frank wrote:
>> how do I get "git send-email" to send the patches gpg signed?
>
> You have to step back and ask what is the end-goal? Do you want
> repudiation/attestation for your own patches, or do you want to be able to
> verify that the patches sent to you by contributors are tamper-evident?

Excellent question. These are probably both addressed by signed e-mails, but quite different from what object-level signing (e.g. "git commit --signed") aims at.

Show 6 quoted lines
> On the kernel side of things, we've been using patatt [1], which supports PGP,
> SSH, and ed25519-signing of patches via a dedicated custom header, a-la DKIM.
>
> [1] https://github.com/mricon/patatt/blob/main/README.rst
>
> -K
Previous: Konstantin Ryabitsev
Message 10 of 10 in “How to gpg signed email patches?”
  1. Klaus FrankApr 13, 2025
  2. Matt HunterApr 13, 2025
  3. Klaus FrankApr 13, 2025
  4. Junio C HamanoApr 14, 2025
  5. brian m. carlsonApr 13, 2025
  6. Klaus FrankApr 14, 2025
  7. brian m. carlsonApr 14, 2025
  8. Junio C HamanoApr 14, 2025
  9. Konstantin RyabitsevApr 14, 2025
  10. Junio C HamanoApr 14, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.