Force signed commits #277
Replies: 2 comments 2 replies
-
|
Especially asking @dloewen2 and @mms-gianni |
Beta Was this translation helpful? Give feedback.
-
|
This came also to my mind. I actually think sign-off is a good idea. But it also has disadvantages. For example, it can be a hurdle for new contributors. The advantage is that it's still possible to trace who made the commit even if the Github account no longer exists. However, it doesn't guarantee that real names and email addresses were used for the sign-off. I'm also aware of larger, well-known projects that made sign-off mandatory. https://github.com/k8s-operatorhub/community-operators/commits/main/ In the beginning, perhaps a hint that it's preferred might be sufficient. There's a Github action that leaves a comment in the PR. https://github.com/marketplace/actions/check-signed-commits-in-pr |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Good Evening,
I am currently in the process of deciding if its reasonable, to force signed commits to every branch.
My thought process is, that these charts come to use in production environments, so atleast knowing / verifying who made what change is important
What is yall´s opinion about this idea?
Beta Was this translation helpful? Give feedback.
All reactions