
Why should we sign git commit?
Git author name and email can easily be fake. Signing a commit will verify that the author is really you.
This practice also helps your commit look more trustworthy when contribute to open source projects.
What is GPG?
GPG (GNU Privacy Guard) is a free tool for encrypting, decrypting, and signing data. It ensures secure communication and data integrity by using public-key cryptography. GPG is commonly used for encrypting emails, signing software, and securely transmitting files. It’s widely supported and integrates with many systems to provide data security and authenticity verification.
How to sign a git commit?
Create GPG key
Ignore this step if you already have a GPG key.
Generate a GPG key pair:
gpg --full-generate-key
Email address should be set to same as your account on GitHub/Gitlab.
Get the secret key
-
List the long form of the GPG keys for which you have both a public and private key. A private key is required for signing commits or tags. From the list of GPG keys, copy the long form of the GPG key ID you'd like to use. In this example, the GPG key ID is
3AA5C34371567BD2:gpg --list-secret-keys --keyid-format=long/Users/hubot/.gnupg/secring.gpg ------------------------------------ sec 4096R/3AA5C34371567BD2 2016-03-10 [expires: 2017-03-10] uid Hubot <hubot@example.com> ssb 4096R/4BB6D45482678BE3 2016-03-10 -
If the email in GPG key is already matched with your GitHub/Gitlab account, move to the next step. If not, add your email to your GPG key. Enter
gpg --edit-key GPG_key_ID, substituting in the GPG key ID you'd like to use. In the following example, the GPG key ID is3AA5C34371567BD2:gpg --edit-key 3AA5C34371567BD2 -
Enter
adduidto add the user ID details:gpg> adduid -
Follow the prompts to supply your real name, email address, and any comments. You can modify your entries by choosing N, C, or E:
Real Name: OCTOCAT Email address: "hubot@example.com" Comment: GITHUB-KEY Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? -
Save the changes:
gpg> save
Add the public key to GitHub/Gitlab
-
Enter
gpg --armor --export GPG_key_ID, substituting in the GPG key ID you'd like to use. In the following example, the GPG key ID is3AA5C34371567BD2:gpg --armor --export 3AA5C34371567BD2 # Prints the GPG key, in ASCII armor format -
Add your public key to git server:
- Github: In
Settings>SSH and GPG keys.
- Gitlab: In
Settings>GPG keys.
- Github: In
Commit
Now you can sign when commit with option -S :
git commit -S -m "commit"
or permanent enable in git config:
git config --global commit.gpgSign true # execute once
git commit -m "commit"
Comments