1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
This document explains how to set up GPG or SSH commit signing for RustChain contributions.
Signed commits provide:
- --
```bash
gpg --full-generate-key
gpg --list-secret-keys --keyid-format=long
```
```bash
git config --global user.signingkey YOUR_KEY_ID
git config --global commit.gpgsign true
git config --global tag.gpgsign true
```
```bash
gpg --armor --export YOUR_KEY_ID
```
```bash
ssh-keygen -t ed25519 -C "your.email@example.com"
```
```bash
git config --global gpg.format ssh
git config --global user.signingkey ~/.ssh/id_ed25519.pub
git config --global commit.gpgsign true
```
Add your SSH public key to GitHub Settings > SSH and GPG keys with "Signing Key" type.
Test your setup:
```bash
git commit -S -m "test: verify signing setup"
git log --show-signature -1
```
Repository maintainers should enable:
- --
```bash
gpgconf --launch gpg-agent
export GPG_TTY=$(tty)
```
```bash
ssh-add -l
ssh-add ~/.ssh/id_ed25519
```
- -