Thread (11 messages) 11 messages, 2 authors, 2016-06-15

Re: [RFC PATCH 4/4] Make git fetch verify signed tags

From: Johannes Schindelin <hidden>
Date: 2016-06-15 22:45:41

Hi,

On Sun, 23 Nov 2008, Deskin Miller wrote:
When git fetch downloads signed tag objects, make it verify them right 
then.  This extends the output summary of fetch to include "(good 
signature)" for valid tags and "(BAD SIGNATURE)" for invalid tags.  If 
the user does not have the correct key in the gpg keyring, gpg returns 
2, verify_tag_sha1 returns -2 and nothing additional is output about the 
tag's validity.
This must be turned off by default, IMO.  You cannot expect each and every 
developer to have gpg _and_ all those public keys installed.

Ciao,
Dscho
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help