{"type":"rich","version":"1.0","author_name":"npub1xqshkqv2g7uea4xzqwvmgjcz7u8vfavw6aazs999v0azsv3w7u3qpymc2p","author_url":"https://nostr.ae/npub1xqshkqv2g7uea4xzqwvmgjcz7u8vfavw6aazs999v0azsv3w7u3qpymc2p","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-05-21\n📝 Original message:Hello Chris,\n\nOn Wed, May 21, 2014 at 6:39 PM, Chris Beams \u003cchris at beams.io\u003e wrote:\n\u003e I'm personally happy to comply with this for any future commits, but wonder\n\u003e if you've considered the arguments against commit signing [1]? Note\n\u003e especially the reference therein to Linus' original negative opinion on\n\u003e signed commits [2].\n\nYes, I've read it. But would his alternative, signing tags, really\nhelp us more here? How would that work? How would we have to structure\nthe process?\n\nAt least signed commits are easy to integrate into the current\ndevelopment process with github - only a different way of merging has\nto be used.\n\n\u003e I came across these when searching for a way to enable signing by default,\n\u003e e.g. a `git config` option that might allow for this. Unfortunately, there\n\u003e isn't one, meaning it's likely that most folks will forget to do this most\n\u003e of the time.\n\nI'll remind people if they forget to do it, but I won't require it. As\nyou say, that would be an extra barrier, and I'm not suggesting this\nbecause I to see people jumping through bureaucratic hoops.\nBut it is a pretty simple thing to do...\n\n\u003e If you're really serious about it, you should probably reject pull requests\n\u003e without signed commits; otherwise, signing becomes meaningless because only\n\u003e honest authors do it, and forgetful or malicious ones can avoid it without\n\u003e penalty.\n\nThis is not because I'm afraid of malicious authors, but because I\nwant to reduce the risk that github hacks would pose.\n\nSomething to watch for would be authors that normally sign pull\nrequests/merges and suddenly don't. Someone malicious may have gained\naccess to their github account. This just adds an extra layer of\nprotection.\n\nCheers,\nWladimir"}
