jarrodldavis/probot-gpg

Only require last commit to be signed

joshbetz opened this issue · 3 comments

Signing all commits isn't necessary and arguably problematic. Any thoughts on only requiring the last commit to be signed?

More Info: https://josh.blog/2016/11/gpg-git

Possibly make it optional via a .github/config.yml file?

Yeah, I can add it as an option in the .github/config.yml

I would actually say that his could be a reasonable default.