Moved to Codeberg; this is a temporary convenience mirror - technomancy/leiningen
ssh-keygen can sign and verify signatures, and it's way better than PGP
Moved to Codeberg; this is a temporary convenience mirror - technomancy/leiningen
Other Git related articles on DEV from me: A clean Git history with Git Rebase and Conventional...
A lot of new hardware security keys (Yubikey, Nitrokey, Titan, etc.) now support FIDO2 (aka U2F aka Webauthn aka Passkey; yes it’s a mess). So does OpenSSH. This spells good news for us, because it is far easier to use than previous hardware security types (eg, PKCS#11 and OpenPGP) with ssh. A key benefit of all this, if done correctly, is that it is actually impossible to access the raw SSH private key, and impossible to use it without the presence of the SK and a human touching it.
How to sign Git commits and tags with SSH keys.