keybase / keybase/keybase-issues
GPG sign commits and tags on github.
Open
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
GPG signing at least tags would be great.
If for nothing else, because if anyone should be signing commits and tags, it should be keybase... lol
But also because of increased security.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue requests GPG signing for GitHub commits and tags but names no repository files or tests. Start by determining the project's current commit and tag release process and the signing constraints; done means the relevant commits and at least tags are verifiably GPG-signed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- git, github
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100