Skip to content

add-verified-gpg-signature-to-git-settings #91

@david-thrower

Description

@david-thrower

Kind of issue: Process Change

After viewing a recent security tutorial and other sources, I am seeing that some frameworks require a local GPG signature for commits [1] before a commit can be merged in. We need to add to the CICD SOP or SOP-0001 a requirement that this setting be applied. The setting to create these signatures is easy to apply [2].

[1] https://garantir.io/three-frameworks-software-supply-chain-security/
[2] https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions