threads / discuss / 53812

GPG Commit Signing Project

Subject: GPG Commit Signing Project

## tl;dr

2 messages between Jul 7, 2020 and Jul 7, 2020.

replies: 1people: 2as markdown or json

Jimit Bhalavat· Jul 7, 2020, 18:01 UTC · lore
Hello Junio,
When we last spoke, David Huseby, my mentor for Hyperledger Git Commit Signing Project, proposed an outline of what we are trying to achieve. We have come to the conclusion that me and him are going to spend the rest of the summer analyzing the format signing infrastructure and will have proposals and questions as we go. I am also going to write a technical design document which will help us analyze the problem. I realize this is a larger long-term project that I think deserves a topic and how would I set a topic up? 
I am also going to be thoroughly reading and understanding the patches from last summer which will help me guide through the format. If you are not the right person to be in contact with, please put me in touch with the right person, or if you don’t mind, please forward this email to them so that we can be in touch. 
I really appreciate all your help, thank you once again, and I will have proposals and questions as we move forward. 
Thank you.

Be well and stay safe, Jimit Bhalavat

Junio C Hamano· Jul 7, 2020, 19:10 UTC · re: Jimit Bhalavat · lore

Re: GPG Commit Signing Project

Jimit Bhalavat <jimit@rams.colostate.edu> writes:
Show 5 quoted lines
> When we last spoke, David Huseby, my mentor for Hyperledger Git
> Commit Signing Project, proposed an outline of what we are trying
> to achieve. We have come to the conclusion that me and him are
> going to spend the rest of the summer analyzing the format signing
> infrastructure and will have proposals and questions as we go.

I thought the conclusion was that there is nothing to do on the git side as your project would wrap the non-GPG signing tool of your choice to have an external interface that is similar to how GPG looks to git and that has the added benefit that the product of your project to interact with tools other than git [*1*]. So...

> I am also going to write a technical design document which will
> help us analyze the problem. I realize this is a larger long-term
> project that I think deserves a topic and how would I set a topic
> up?

... your longer-term plan may very well deserve a detailed technical design document, but I am not sure what help our project can give (other than obvious things like saying "good luck").

Sorry for not being able to help all that much.
[Reference]
*1* https://lore.kernel.org/git/xmqqd0642p3q.fsf@gitster.c.googlers.com/
 

← back to recent threads