Skip to content

Clarify commit signature trust models (GPG and S/MIME) #18328

Open
@LecrisUT

Description

@LecrisUT

Feature Description

Currently there is a confusion when using the Collaborator trust model for commit signature, particularly in the commit view. This causes frequent confusions to the users. I suggest that we implement at least one or preferably both:

  1. Add a tooltip in the commit view that pops-up an explanation of untrusted user (UI wise something like in this tutorial). Explanation could be: This commit is correctly signed by ${user}(${email}), but ${user} is not a trusted collaborator of this repository
  2. Change the default trust model to Committer

For reference attached is a screenshot of one of the places where a tooltip pop-up would clarify

Screenshots

image
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    type/enhancementAn improvement of existing functionalitytype/proposalThe new feature has not been accepted yet but needs to be discussed first.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions