Skip to content

Request: gpg sign all commits #2357

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
rbarker-dev opened this issue May 6, 2025 · 0 comments
Open

Request: gpg sign all commits #2357

rbarker-dev opened this issue May 6, 2025 · 0 comments

Comments

@rbarker-dev
Copy link

I noticed that the yq project isn't requiring commits to be signed from internal or external contributors. I would recommend enforcing gpg signing on all commits so that the consumers of the project can visually verify that commits can be trusted.

I believe there's a repository level setting under the General tab
Require contributors to sign off on web-based commits which can be checked.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant