What is Nostr?
Filippo Valsorda :go: /
npub1whz…kn2m
2023-06-06 11:59:33
in reply to nevent1q…3zue

Filippo Valsorda :go: on Nostr: git commit signing by the Committer is a broken model: it requires the key to be ...

git commit signing by the Committer is a broken model: it requires the key to be available in every env (hence the "signed by GitHub" verified commits); it asks developers to manage keys; it has no good support for key rotation; and signs a statement of dubious value ("this is a commit I made or rebased at some point").

git push signing is better, but really what matters is "what did the code host serve as main at time T" and that's a perfect statement to put in a code host-maintained tlog.
Author Public Key
npub1whzyg92c6fsvpjjcnn504z0a2pfwenctp872sgmedqg2np4drj8qwakn2m