Github Security: Only allow verified commit #418
Closed
gsnw-sebast
started this conversation in
General
Replies: 3 comments 3 replies
-
|
Our “Rebase and Merge” method therefore breaks the verification process. |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
I am not convinced that this is useful. Whoever controls the GitHub account can change the GPG key. Anyone can create a GPG key for any email address. It seems to me as if this would just add more work for us without significant benefit. |
Beta Was this translation helpful? Give feedback.
3 replies
-
|
I hereby close the discussion. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
What do you think of the idea of only allowing verified commits?
It does not provide 100% security, but it could contribute to it because the GPG key must match the email address and GPG key stored in the GitHub account.
Beta Was this translation helpful? Give feedback.
All reactions