Conversation

it'd be nice if github had better support for rewriting history as part of a PR review process, even something really basic like squashing groups of commits
1
31
The signatures only sign the object they get embedded into and otherwise depend on a graph of SHA-1 hashes to provide security. It's pretty far from ideal. It'd ideally use Git notes for detached signatures and wouldn't hard-wire GPG as the only option, among other things.
1
1