Search
Setup for Free
UB
Universal Blue
•
2y ago
•
27 replies
RoyalOughtness
RoyalOughtness - one suggestion for repos acros...
one suggestion for repos across the ublue github org
: requiring signed commits in branch policies
Universal Blue
Join
Universal Blue is a manufacturing process that focuses on community-driven desktop and server operating systems.
27,012
Members
View on Discord
Resources
ModelContextProtocol
ModelContextProtocol
MCP Server
Similar Threads
Was this page helpful?
Yes
No
© 2026 Hedgehog Software, LLC
Twitter
GitHub
Discord
System
Light
Dark
More
Communities
Docs
About
Terms
Privacy
R
RoyalOughtness
OP
•
7/12/24, 7:13 PM
most commits are verified
/signed already
, but mandating this for all primary branches is a good defense against supply chain attacks
J
j0rge
•
7/12/24, 7:19 PM
https://github.com/orgs/ublue-os/projects/1?pane=issue&itemId=61240671
J
j0rge
•
7/12/24, 7:19 PM
this
'll be covered under the minder stuff
J
j0rge
this'll be covered under the minder stuff
R
RoyalOughtness
OP
•
7/12/24, 7:23 PM
even better
J
j0rge
•
7/12/24, 7:23 PM
yeah that
'll cover everything and will autocorrect missettings too
J
j0rge
yeah that'll cover everything and will autocorrect missettings too
R
RoyalOughtness
OP
•
7/12/24, 7:23 PM
it integrates with github apis to set stuff like mandating signed commits
?
J
j0rge
•
7/12/24, 7:24 PM
we can enforce any github setting
R
RoyalOughtness
OP
•
7/12/24, 7:24 PM
that
's great
J
j0rge
•
7/12/24, 7:24 PM
like right now if we set up a new repo we gotta go and set up all the shit
R
RoyalOughtness
OP
•
7/12/24, 7:24 PM
i
'll be looking into this for my projects
J
j0rge
•
7/12/24, 7:24 PM
they run a service
, fully OSS
J
j0rge
•
7/12/24, 7:24 PM
https://github.com/stacklok/minder
GitHub
GitHub - stacklok/minder: Software Supply Chain Security Platform
Software Supply Chain Security Platform
. Contribute to stacklok
/minder development by creating an account on GitHub
.
J
j0rge
•
7/12/24, 7:24 PM
or run it yourself
R
RoyalOughtness
OP
•
7/12/24, 7:25 PM
im assuming they don
't require standing access
?
R
RoyalOughtness
OP
•
7/12/24, 7:25 PM
since that would be
R
RoyalOughtness
OP
•
7/12/24, 7:25 PM
i
'll look into it more later
J
j0rge
•
7/12/24, 7:25 PM
I haven
't had a chance to dig into it
, hence the placeholder ticket
, heh
R
RoyalOughtness
OP
•
7/12/24, 7:25 PM
ideally they
'd be using OBO tokens or something like that
R
RoyalOughtness
OP
•
7/12/24, 7:26 PM
where all authn
/z is handled by github itself
H
HikariKnight
•
7/12/24, 9:03 PM
I have noticed signing commits is unreliable for me on GitHub
. Seems like some get signed others don
't
(obviously web edits always get signed
)
M
M2
•
7/12/24, 9:11 PM
webedit is the only thing that get verified sign commits for me
H
HikariKnight
I have noticed signing commits is unreliable for me on GitHub. Seems like some g...
R
RoyalOughtness
OP
•
7/12/24, 11:03 PM
there
's a config you have to set locally for git to make it so that
git commit
git commit
automatically signs them
R
RoyalOughtness
OP
•
7/12/24, 11:04 PM
https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-ssh-key
GitHub Docs
Telling Git about your signing key - GitHub Docs
R
RoyalOughtness
OP
•
7/12/24, 11:04 PM
@M2
@HikariKnight
R
RoyalOughtness
OP
•
7/12/24, 11:04 PM
assuming you already have a GPG key
R
RoyalOughtness
assuming you already have a GPG key
H
HikariKnight
•
7/12/24, 11:22 PM
Yup but also I think my gpg key expires soon as I made it many many years ago
M
M2
•
7/12/24, 11:39 PM
It works on my work code base
.
.
.
H
HikariKnight
•
7/13/24, 12:43 AM
For me the signing is a DND dice roll
git commit
git commit
Similar Threads
Repos Thread
UB
Universal Blue / 💾ublue-dev
2y ago
Suggestion
UB
Universal Blue / 🛟bazzite-help
7mo ago
Suggestion Regarding Bluetooth
UB
Universal Blue / 🛟bazzite-help
10mo ago
Merge Kernel Cache and Akmods Repos
UB
Universal Blue / 💾ublue-dev
14mo ago