Elena' s AI Blog

PGP and Git Verification Series

Elena Daehnhardt

Midjourney AI-generated art
Image credit: Illustration created with Midjourney, prompt by the author.
Image prompt

“An illustration representing cloud computing”

PGP and Git Verification: A Practical Guide

GPG often feels intimidating, yet a few good habits turn it into everyday protection: signed commits, safely managed keys, and verifiable releases. This seven-part series walks from the basic identity problem to enforcing verified commits in CI.

What You’ll Learn

  • Part 1: The Author Identity Problem - Why Git authorship can be forged, and public/private key cryptography in plain language
  • Part 2: Setting Up GPG and Automatic Commit Signing - Generating strong keys and configuring Git
  • Part 3: Master Keys, Subkeys and Key Rotation - Daily signing without risking your primary key
  • Part 4: Disaster Recovery - Revocation certificates and safe key backups
  • Part 5: Signing Releases and Enforcing Verified Commits - Supply chain security for open-source and Python projects
  • Part 6 (Bonus): Signing and Encrypting Email with PGP - Reusing your keys for email
  • Part 7: Inside a Signed Git Commit - An advanced look at objects, signatures and attacks
  • Part 6 (Bonus): Signing and Encrypting Email with PGP - Reusing your keys for email
  • Part 7: Inside a Signed Git Commit - An advanced look at objects, signatures and attacks

Series Progress

0 of 7 posts published


All Posts in This Series

Part 1: The Author Identity Problem: Why Git Commits Can Be Forged

Coming Soon

Anyone can set user.name and user.email in Git, and timestamps are just text. This first part shows how easily a commit can be forged and explains public and private key cryptography in plain language, so signing makes sense before we set anything up.

This post is currently being written and will be published soon.

The Author Identity Problem: Why Git Commits Can Be Forged

Part 2: Setting Up GPG and Automatic Git Commit Signing

Coming Soon

Install GPG, generate a strong Ed25519 or 4096-bit RSA key, and configure Git to sign every commit automatically. I also show how to add the public key to GitHub and get the green Verified badge.

This post is currently being written and will be published soon.

Setting Up GPG and Automatic Git Commit Signing

Part 3: Master Keys, Subkeys and Key Rotation in GPG

Coming Soon

Why your primary key should stay offline, how to create a dedicated signing subkey, and how to set and extend expiry dates so a leaked daily key is a small problem, not a disaster.

This post is currently being written and will be published soon.

Master Keys, Subkeys and Key Rotation in GPG

Part 4: GPG Disaster Recovery: Revocation Certificates and Key Backups

Coming Soon

Lost laptop, forgotten passphrase, leaked key: generate a revocation certificate in advance, back up your keys safely with a password manager and offline storage, and practise restoring them.

This post is currently being written and will be published soon.

GPG Disaster Recovery: Revocation Certificates and Key Backups

Part 5: Signing Releases and Enforcing Verified Commits in CI

Coming Soon

Sign release tags and Python package artifacts, and enforce signed commits with GitHub branch protection and CI checks, so your software supply chain can be verified end to end.

This post is currently being written and will be published soon.

Signing Releases and Enforcing Verified Commits in CI

Part 6: Bonus: Signing and Encrypting Email with PGP

Coming Soon

Bonus material: use the PGP skills from this series for email. Add an encryption subkey, exchange public keys, and sign and encrypt messages in a mail client.

This post is currently being written and will be published soon.

Bonus: Signing and Encrypting Email with PGP

Part 7: Inside a Signed Git Commit: Objects, Signatures and Attacks

Coming Soon

An advanced look under the hood: how Git stores a commit signature in the gpgsig header, what exactly gets signed, how verification and trust work, and which attacks signing does and does not stop.

This post is currently being written and will be published soon.

Inside a Signed Git Commit: Objects, Signatures and Attacks

Getting Started

This series is coming soon. The first post introduces the foundations.


Who Is This Series For?

  • Developers who want their commits and releases to be verifiably theirs
  • Open-source maintainers who need to trust contributions and publish signed releases
  • Technical writers and creators who care about digital authenticity and ownership
All Posts