Conversation

Replying to and
It's a poorly designed feature even for tags. Tags are clearly meant to be immutable and Git doesn't separate tags from different sources. If you wanted to rotate the signing key, you would need to create new tags or ignore that the existing tags couldn't be verified anymore.
1
3
Replying to and
Signatures should be based on Git notes so they can be attached to an object after the fact and there wouldn't be the limit of only having a single signature from one person. It also avoids having it tied to a horrible legacy approach to signing (GPG). Still depends on SHA-1...
1
2
Show replies