+_Update_: The Git Book now has a "chapter on GPG-signing": which is also quite good.
This is a guest post from "Ryan Brown.":
As a developer you use code written by other people _all the time_. To keep upstream changes from breaking your code, you depend on release numbers. Libraries like "bootstrap": use "git tags": to track releases and make them available for download.

