From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org [79.124.17.100]) by master.gitmailbox.com (Postfix) with ESMTP id 4BDDA43D2F for ; Mon, 8 Aug 2022 22:37:03 +0000 (UTC) Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 1E94268B6A7; Tue, 9 Aug 2022 01:37:01 +0300 (EEST) Received: from relay7-d.mail.gandi.net (relay7-d.mail.gandi.net [217.70.183.200]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 70B4368B580 for ; Tue, 9 Aug 2022 01:36:55 +0300 (EEST) Received: (Authenticated sender: michael@niedermayer.cc) by mail.gandi.net (Postfix) with ESMTPSA id 71F7520002 for ; Mon, 8 Aug 2022 22:36:54 +0000 (UTC) Date: Tue, 9 Aug 2022 00:36:53 +0200 From: Michael Niedermayer To: FFmpeg development discussions and patches Message-ID: <20220808223653.GX2088045@pb2> References: <20220808145008.26162-1-michael@niedermayer.cc> <20220808145008.26162-1-michael@niedermayer.cc-N8xvyjN----2> MIME-Version: 1.0 In-Reply-To: Subject: Re: [FFmpeg-devel] [RFC] git and signing commits and tags X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Content-Type: multipart/mixed; boundary="===============3884253442617282746==" Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" Archived-At: List-Archive: List-Post: --===============3884253442617282746== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="s3puAW9DMBtS2ARW" Content-Disposition: inline --s3puAW9DMBtS2ARW Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Aug 08, 2022 at 09:26:52PM +0200, Lynne wrote: > Aug 8, 2022, 16:50 by michael@niedermayer.cc: >=20 > > Given the recent server issues, i wonder if we should suggest/recommand > > and document signing commits and tags > > > > i tried to push such commit to github and it nicely says "verified" > > https://github.com/michaelni/FFmpeg/commit/75f196acd16fb0c0ca7a94f0c660= 72e7c6f736bf > > > > Ive generated a new gpg key for this experiment as i dont have my > > main key on the box used for git development and also using more > > modern eliptic curve stuff (smaller keys & sigs) > > i will upload this key to the keyservers in case it becomes the > > one i use for git. > > >=20 > I sign all of my commits,=20 I didnt notice, but thats good as it also proofs it works with no ill sideeffects Where can i find your public key ? it seems its not on the keyservers i che= cked > I think it should be recommended but > not required. yes, for now, thats certainly the right path. In the future this should maybe be reevaluated >=20 > One downside is that you can sign commits from others with your > own key (for instance when pushing a patch from someone along > with your commits, and signing all at once via rebase), which can be > misleading, so it takes some work to reorder commits or push them > in stages so this doesn't happen. It makes sense that it's the > committer who's signing it, but git or github don't make a distinction > when it comes to signing. I dont see much harm if other commits are signed too.=20 thx [...] --=20 Michael GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB I do not agree with what you have to say, but I'll defend to the death your right to say it. -- Voltaire --s3puAW9DMBtS2ARW Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iF0EABEIAB0WIQSf8hKLFH72cwut8TNhHseHBAsPqwUCYvGQAQAKCRBhHseHBAsP qxSQAKCEUHZGMOCgMTIOine7jujql0lRDACfXf9Vc++C6AmvrfXlhzizxt+hgOs= =Y45+ -----END PGP SIGNATURE----- --s3puAW9DMBtS2ARW-- --===============3884253442617282746== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe". --===============3884253442617282746==--