Skip to content

Request: Can the signed commits PR requirement be removed? #126

Closed Answered by canterberry
vyas-n asked this question in Q&A
Discussion options

You must be logged in to vote

Signed commits are a requirement across the Twuni organization, so for as long as the repo is hosted here, signed commits are a requirement. I understand that it adds friction because it requires something more of contributors than the code change itself, but the requirement does have merit!

It creates cryptographically strong and service-agnostic provenance, authenticity, and integrity for commit history, defending contributions against tampering by myself or others with privileged access to the GitHub repo. It's also a small additional safeguard against contributions from bots and other potential malicious actors.

It has not been my experience or observation that configuring git for sig…

Replies: 1 comment 2 replies

Comment options

vyas-n
Apr 25, 2024
Maintainer Author

You must be logged in to vote
2 replies
@canterberry
Comment options

Answer selected by vyas-n
@vyas-n
Comment options

vyas-n Apr 25, 2024
Maintainer Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants