Re: Requiring GPG Commit Signing
| From: | John Coggeshall | Date: | Wed, 03 Apr 2024 17:28:53 +0000 |
| Subject: | Re: Requiring GPG Commit Signing | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-122912@lists.php.net to get a copy of this message | ||
> > Having GPG key requirements is all fine and dandy I suppose, but my
> > tongue-in-cheek comment above has a real point behind it: GPG keys
> > don't mean jack if you can't trust who owns the key.
>
> GitHub doesn't show the web of trust anyway, just "verified". Command
> line GIT doesn't either, just:
>
That's really unfortunate (why even bother). IMO without some sort of web of trust verification
process for GPG, this just feels like added barriers for no actual win. In fact, if anything I think
it's more likely to give the project a false sense of security.
Cheers,
John