Why commits by github don't show 'verified' (signed commits)?

Viewed 4165

I got the git commits from my local repo to show 'verified' on github, by setting up the gpg key.

But why my commits by github (while I am on github) don't show up as 'verified'? It shows nothing, indicating github sees them as unverified commits. Is this expected or maybe I need to configure something on github?

Thanks.

3 Answers

At some point in Fall 2020, possibly between 1-20 October, GitHub changed the way they handle GPG key commit verifications rebases where ONLY the git COMMITTER_DATE is changed.

So here's my very normal usecase flow:

  1. I find a very small problem in a commit for a feature that hasn't been released yet.
  2. I commit it then rebase away the transient fix commit.
  3. Because more than 1 day has elapsed, github will report my activity of the original file as occuring today.
  4. I fix that by doing git rebase --committer-date-is-author-date <HASH>, which resets the GitHub file-modded date to the commit's datetime, not today/now.

Before 20 October, I had never had a problem in over 8 years doing these steps.

Now, all of a sudden, GitHub is showing all commits caught up in this rebase as being unverified:

enter image description here

You can see for yourself over at https://github.com/hopeseekr/BashScripts/commits/fucked_up_gpg_verifications

The error reported? "No user is associated with the committer email.", which is patently ridiculous, as all the commits share the same email address and it's the main one on the account.

You cannot sign commits/tags created via GitHub web interface. Only local commits/tags can be signed.

This is because a signing key consists of two parts — public and private. And private keys MUST NEVER LEAVE your computer.

The public part can encrypt data, the private decrypt it so only you can read the encrypted data. The private key signs data, the public key verifies so only you can sign with your key but anyone can verify your signatures.

When you upload a GPG key to GitHub you only upload the public key so GitHub can only verify signed commits/tags but cannot sign them.

Not exactly. If you are committing something on GitHub.com web (e.g. editing the README.md file by clicking the pencil icon and then commit by clicking the commit button on GitHub web), the expected behavior is that the commit is signed by Github.com (using GPG key ID: 4AEE18F83AFDEB23 in my case)

Screenshot of GitHub signature

Related