git-verify-tag script
From: Jan Harkes <jaharkes@cs.cmu.edu>
Date: 2016-06-15 22:42:00
From: Jan Harkes <jaharkes@cs.cmu.edu>
Date: 2016-06-15 22:42:00
Here is a script to simplify validating the gpg signature created by
git-tag-script. Might be useful to add to the git tree so that people
don't have to search for the right post in the git mailinglist archives
when they want to validate a tag.
Jan
----
#!/bin/sh
GIT_DIR=${GIT_DIR:-.git}
tag=$1
[ -f "$GIT_DIR/refs/tags/$tag" ] && tag=$(cat "$GIT_DIR/refs/tags/$tag")
git-cat-file tag $tag > .tmp-vtag || exit 1
cat .tmp-vtag | sed '/-----BEGIN PGP/Q' | gpg --verify .tmp-vtag -
rm -f .tmp-vtag