stats.radicle.at

Sign your commits with your Radicle key

For anyone who commits to a repository on Radicle. Signed with your Radicle key, your commits show on stats.radicle.at as yours in the activity of each repository you work on. Once 2 or more repositories listed here name you as a delegate, your commits also show on an identity page of your own.

Sign your commits from now on

A signed commit carries proof that your key made it. An unsigned one carries only a name and an email address, which anyone can type, so it cannot be shown as yours for certain.

Run these once, in a terminal:

git config --global gpg.format ssh
git config --global user.signingkey "$(rad path)/keys/radicle.pub"
git config --global commit.gpgsign true

From then on git signs every commit you make on this computer. To sign in one repository only, run the same three lines inside it without --global.

If your Radicle key has a passphrase, run this each time you start your computer, so git can sign without asking for it at every commit:

rad auth

Make sure your signed commits count

A signature alone is not enough. The commit also has to land where stats.radicle.at looks.

You already sign with another SSH key

Commits signed with another SSH key show as yours here once you prove you hold both keys.

  1. Email admin@radicle.tools your Radicle identity and the public half of that other key. These print them (use your key's file name if it is not id_ed25519):
    rad self --did
    cat ~/.ssh/id_ed25519.pub
    Send only the .pub line. Never send a private key.
  2. We reply with a short statement naming both keys, and two commands that sign it, one with each key. Run them and send back the two signature files they write.
  3. Once we add the link, the next nightly update shows the commits signed with that key as yours.

Your older, unsigned commits

A commit cannot be signed after it is made without rewriting it. An unsigned commit can still show as yours, marked matched by email, when its author email is the one on commits you did sign in the same repository. That is a guess, not proof, so those commits are drawn hollow and counted apart from signed ones.

Rewriting old commits to sign them is possible but not advised. Each one, and every commit after it, gets a new commit ID, and everyone who cloned the repository has to repair their copy by hand.