Bastian Blank schreef op 25-5-2015 om 10:33 AM: > Much worse, do you trust all your development machines with your private > key?
I do not. That is why I keep my private signature key on my smartcard. I sign every commit on all of my machines. You can put this in your .gitconfig to always sign your commits: [commit] gpgsign = true -- Kind regards, Christiaan de Die le Clercq PGP: 0x9FB800372F2546D8
signature.asc
Description: OpenPGP digital signature