Sign your commits with your Radicle key
For anyone who commits to a repository on Radicle. Signed with your Radicle key, your commits show on stats.radicle.at as yours in the activity of each repository you work on. Once 2 or more repositories listed here name you as a delegate, your commits also show on an identity page of your own.
Sign your commits from now on
A signed commit carries proof that your key made it. An unsigned one carries only a name and an email address, which anyone can type, so it cannot be shown as yours for certain.
Run these once, in a terminal:
git config --global gpg.format ssh
git config --global user.signingkey "$(rad path)/keys/radicle.pub"
git config --global commit.gpgsign trueFrom then on git signs every commit you make on this computer. To sign in one repository
only, run the same three lines inside it without --global.
If your Radicle key has a passphrase, run this each time you start your computer, so git can sign without asking for it at every commit:
rad authMake sure your signed commits count
A signature alone is not enough. The commit also has to land where stats.radicle.at looks.
- Only commits on a repository's default branch count.
- radicle.at must have your fork, your own copy of the repository. It gets it when you
git pushto the repository with your Radicle node running. - A maintainer who squashes or rebases your patch while merging it makes new commits that carry their signature, not yours. A rebased commit can still show as yours, matched by email; a squashed one cannot.
You already sign with another SSH key
Commits signed with another SSH key show as yours here once you prove you hold both keys.
- Email admin@radicle.tools your Radicle identity
and the public half of that other key. These print them (use your key's file name if it is
not
id_ed25519):Send only therad self --did cat ~/.ssh/id_ed25519.pub.publine. Never send a private key. - We reply with a short statement naming both keys, and two commands that sign it, one with each key. Run them and send back the two signature files they write.
- Once we add the link, the next nightly update shows the commits signed with that key as yours.
Your older, unsigned commits
A commit cannot be signed after it is made without rewriting it. An unsigned commit can still show as yours, marked matched by email, when its author email is the one on commits you did sign in the same repository. That is a guess, not proof, so those commits are drawn hollow and counted apart from signed ones.
Rewriting old commits to sign them is possible but not advised. Each one, and every commit after it, gets a new commit ID, and everyone who cloned the repository has to repair their copy by hand.