Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upGitHub is where the world builds software
Millions of developers and companies build, ship, and maintain their software on GitHub — the largest and most advanced development platform in the world.
Please use gpg signed release tags #479
Comments
|
Are you suggesting a project or a personal key? I am not in the strong set, personally, but I can get someone nearby to sign me. |
|
I'll have a look at proper signing as well. Since we don't build much (except for the Windows stuff), it's probably best to do on a personal level. |
|
We are now GPG signing the release tags! Here are the details and fingerprint meanwhile:
|
Hi,
could you please sign your git tags with a GPG key via the "-s" option of git tag? If I can establish a trust path from my key to yours this would give me an extra level of confidence that I'm not downloading a tampered version of your code.
Thank you, Thomas Koch