Please use gpg signed release tags #343

Closed
opened 2026-02-20 23:01:34 -05:00 by deekerman · 3 comments
Owner

Originally created by @thkoch2001 on GitHub (Oct 20, 2012).

Originally assigned to: @phihag on GitHub.

Hi,

could you please sign your git tags with a GPG key via the "-s" option of git tag? If I can establish a trust path from my key to yours this would give me an extra level of confidence that I'm not downloading a tampered version of your code.

Thank you, Thomas Koch

Originally created by @thkoch2001 on GitHub (Oct 20, 2012). Originally assigned to: @phihag on GitHub. Hi, could you please sign your git tags with a GPG key via the "-s" option of git tag? If I can establish a trust path from my key to yours this would give me an extra level of confidence that I'm not downloading a tampered version of your code. Thank you, Thomas Koch
deekerman 2026-02-20 23:01:34 -05:00
Author
Owner

@FiloSottile commented on GitHub (Oct 22, 2012):

Are you suggesting a project or a personal key? I am not in the strong set, personally, but I can get someone nearby to sign me.

@FiloSottile commented on GitHub (Oct 22, 2012): Are you suggesting a project or a personal key? I am not in the strong set, personally, but I can get someone nearby to sign me.
Author
Owner

@phihag commented on GitHub (Oct 26, 2012):

I'll have a look at proper signing as well. Since we don't build much (except for the Windows stuff), it's probably best to do on a personal level.

@phihag commented on GitHub (Oct 26, 2012): I'll have a look at proper signing as well. Since we don't build much (except for the Windows stuff), it's probably best to do on a personal level.
Author
Owner

@FiloSottile commented on GitHub (Jan 2, 2013):

We are now GPG signing the release tags!
However, my key is still not is the strong set. I'm working on it, but in Italy it is difficult...

Here are the details and fingerprint meanwhile:

pub   4096R/D977155C 2011-02-18 [expires: 2013-02-17]
      Key fingerprint = 9524 4D9F EE39 0B71 25A3  4708 3CD8 8EE0 D977 155C
uid                  Filippo Valsorda (FiloSottile) <filosottile.wiki@gmail.com>
uid                  Filippo Valsorda <filippo.valsorda@gmail.com>
uid                  Filippo Valsorda (Own site) <filosottile@pytux.it>
uid                  Filippo Valsorda (Own server) <filosottile@filosottile.info>
sub   4096R/F665357B 2011-02-18 [expires: 2013-02-17]
@FiloSottile commented on GitHub (Jan 2, 2013): We are now GPG signing the release tags! However, my key is still not is the strong set. I'm working on it, but in Italy it is difficult... Here are the details and fingerprint meanwhile: ``` pub 4096R/D977155C 2011-02-18 [expires: 2013-02-17] Key fingerprint = 9524 4D9F EE39 0B71 25A3 4708 3CD8 8EE0 D977 155C uid Filippo Valsorda (FiloSottile) <filosottile.wiki@gmail.com> uid Filippo Valsorda <filippo.valsorda@gmail.com> uid Filippo Valsorda (Own site) <filosottile@pytux.it> uid Filippo Valsorda (Own server) <filosottile@filosottile.info> sub 4096R/F665357B 2011-02-18 [expires: 2013-02-17] ```
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/youtube-dl-ytdl-org#343
No description provided.