Signing Key Interface For External Keys #6235

Open
opened 2025-11-02 06:49:21 -06:00 by GiteaMirror · 1 comment
Owner

Originally created by @xloem on GitHub (Nov 1, 2020).

It would be nice if there were a way to provide keys that are likely to sign commits in a repository, but aren't actually owned by any users, so that these signatures can be verified. Maybe in a repository administration interface?

If that were done, then it might be nice to display a warning if there are commits that can't be verified. Making that eventually possible could really help code integrity, I think.

Originally created by @xloem on GitHub (Nov 1, 2020). It would be nice if there were a way to provide keys that are likely to sign commits in a repository, but aren't actually owned by any users, so that these signatures can be verified. Maybe in a repository administration interface? If that were done, then it might be nice to display a warning if there are commits that can't be verified. Making that eventually possible could really help code integrity, I think.
GiteaMirror added the type/proposaltopic/commit-signing labels 2025-11-02 06:49:21 -06:00
Author
Owner

@zeripath commented on GitHub (Nov 2, 2020):

It is intended to add keyring support as another trustmodel.

@zeripath commented on GitHub (Nov 2, 2020): It is intended to add keyring support as another trustmodel.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/gitea#6235