Would be really cool to see signed tags in the UI. Other forges have this and it would be cool to have this addition! I am willing to help implement this but would need to know where to start.
Monorepo for Tangled
tangled.org
Feature Request - Signed Git Tags #407
open
opened by
ethanholz.com
agreed! as i understand it, there are two scenarios:
commitverifypackage to do this. its not possible to create signed lightweight tags as far as i knowcommitverify, say,tagverifythat verifies the the signature of the tag given the (key, fingerprint, payload) triple (or just share some of the verification logic among commit and tag verification)in the second scenario, calculating the payload is the tricky bit, IIRC figuring out the payload for commits was just reading through in this file to see how git does it. it probably has some info about the payload data for tags. my guess is it would need the following (one element per line):
object: hash of the commit this tag is referring totype: has to be set tocommittag: name of the tag, likev1.13.0-alphatagger: name, email address and time of tagging, similar tocommitterin commitsi should also mention, we only support ssh signing, and not GPG signing.
jjdoes not presently support tagging natively, so you'd need to create signed tags viagitonly, the following git config is necessary: