Skip to content

Comment on Linus Torvalds: “GitHub creates useless garbage merges”parent

Comments

Says it signs the commit with its own key. I guess you have to trust GitHub.

Well, yes. The question was whether you can sign _on GitHub_, so your private key has to be available to GitHub. You can always sign locally if you don't trust GitHub.

What else would they be signing with? They don’t have your key obviously

Well that was my point - I wonder why we haven't set up a system that lets me sign the merge commit. Otherwise it's a commit purported to be authored by me but when you look it's actually signed by someone else.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.