carvel-dev / carvel-dev/kapp-controller
[fetch] support verifying signed git commits
Open
awaiting-input
carvel-accepted
enhancement
- Dominant language
- Go
- Stars
- 323
- Forks
- 127
- Avg merge
- 2d 16h
- Merged PRs (30d)
- 4
Description
It would be really cool if the git source could verify a commit was signed with a GPG signature. This seems like a nice middle ground between not really wanting to give our GitLab access to a serviceAccount with really broad permissions, but also not wanting to set up really fine grained deployment roles per application.
Contributor guide
Assessment
This issue has not been assessed yet.