You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
heri16
changed the title
Ensure all commits signed by developer Keybase keys
Ensure all commits signed by contributor PGP keys from Keybase.io
Oct 25, 2018
Description
All commits pushed to GitHub should be cryptographic signed by the developer PGP keys that are published on Keybase.io .
This should apply to all contributors as standard Git commits are inherently weak against identity spoofing / impersonation.
The Heartbleed Openssl incident teaches us that it would be bad if we could not trace exactly who made the changes that led to the vulnerability.
See: https://help.github.com/articles/signing-commits/
The text was updated successfully, but these errors were encountered: