For one of the projects I'm working on, it's contractually important that our source code has strong audit capabilities--we need to be able to determine who made (or at least authorized) each change. For git, this means using the --gpg-sign option for commit (usernames are not sufficient, since it's trivial to spoof someone's username).
Is it possible to do this using Sourcetree? Is anyone else trying to do this as well?
Hi Neil,
This'll be in the next major Mac version if you're on the Mac. If you're using Windows then it won't be around for a while yet.
Cheers
Kieran,
I'm not sure this is actually working in 1.7.0. I have a gpg key so I entered by path to gpg (in this case /opt/local/bin/gpg since I installed via macports). When I try and enable the "sign all commits" it says there are no keys.
I even tried installing the GPGSuite from https://gpgtools.org/ with no dice. ST just doesn't see I have keys.
Hi Steve,
If you're using GPGTools then try the following path: /usr/local/MacGPG2/bin
That's what I use for mine and it works fine. There's probably a couple of reasons in your case. Firstly you need to specify the folder path, not to the file itself (I think if you copy/paste paths it overrides the restrictions to specify folder paths only) and it wants to know about gpg2 rather than gpg which is in the path.
Try that path and see how it goes.
Cheers!
I see it's still not available on Windows - 3 years later... Frustrating.
It looks like you're new here. Sign in or register to get started.