Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The code would not be signed by Linus; you do not know his private key.

If I as a developer then pull and verify signatures, I would note that commit was unsigned and expect the commit to be compromised.



But you cannot sign commits in git, only tags, right?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: