-
-
Notifications
You must be signed in to change notification settings - Fork 6.1k
Open
Labels
type/proposalThe new feature has not been accepted yet but needs to be discussed first.The new feature has not been accepted yet but needs to be discussed first.
Description
Feature Description
For security reasons, revoking a GPG / SSH key must not invalidate existing commits signatures as this discourages users to follow security best practices (immediately revoke a key when there is any doubt about a possible compromise, key rotations...).
This is the behavior adopted by GitHub: https://docs.github.com/en/authentication/managing-commit-signature-verification/about-commit-signature-verification#persistent-commit-signature-verification
Screenshots
No response
lunny
Metadata
Metadata
Assignees
Labels
type/proposalThe new feature has not been accepted yet but needs to be discussed first.The new feature has not been accepted yet but needs to be discussed first.