<oembed><type>rich</type><version>1.0</version><author_name>npub1xqshkqv2g7uea4xzqwvmgjcz7u8vfavw6aazs999v0azsv3w7u3qpymc2p</author_name><author_url>https://nostr.ae/npub1xqshkqv2g7uea4xzqwvmgjcz7u8vfavw6aazs999v0azsv3w7u3qpymc2p</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-05-21&#xA;📝 Original message:Hello Chris,&#xA;&#xA;On Wed, May 21, 2014 at 6:39 PM, Chris Beams &lt;chris at beams.io&gt; wrote:&#xA;&gt; I&#39;m personally happy to comply with this for any future commits, but wonder&#xA;&gt; if you&#39;ve considered the arguments against commit signing [1]? Note&#xA;&gt; especially the reference therein to Linus&#39; original negative opinion on&#xA;&gt; signed commits [2].&#xA;&#xA;Yes, I&#39;ve read it. But would his alternative, signing tags, really&#xA;help us more here? How would that work? How would we have to structure&#xA;the process?&#xA;&#xA;At least signed commits are easy to integrate into the current&#xA;development process with github - only a different way of merging has&#xA;to be used.&#xA;&#xA;&gt; I came across these when searching for a way to enable signing by default,&#xA;&gt; e.g. a `git config` option that might allow for this. Unfortunately, there&#xA;&gt; isn&#39;t one, meaning it&#39;s likely that most folks will forget to do this most&#xA;&gt; of the time.&#xA;&#xA;I&#39;ll remind people if they forget to do it, but I won&#39;t require it. As&#xA;you say, that would be an extra barrier, and I&#39;m not suggesting this&#xA;because I to see people jumping through bureaucratic hoops.&#xA;But it is a pretty simple thing to do...&#xA;&#xA;&gt; If you&#39;re really serious about it, you should probably reject pull requests&#xA;&gt; without signed commits; otherwise, signing becomes meaningless because only&#xA;&gt; honest authors do it, and forgetful or malicious ones can avoid it without&#xA;&gt; penalty.&#xA;&#xA;This is not because I&#39;m afraid of malicious authors, but because I&#xA;want to reduce the risk that github hacks would pose.&#xA;&#xA;Something to watch for would be authors that normally sign pull&#xA;requests/merges and suddenly don&#39;t. Someone malicious may have gained&#xA;access to their github account. This just adds an extra layer of&#xA;protection.&#xA;&#xA;Cheers,&#xA;Wladimir</html></oembed>