PGP and Git Verification SeriesElena Daehnhardt |
Image credit: Illustration created with Midjourney, prompt by the author.
Image prompt“An illustration representing cloud computing” |
PGP and Git Verification: A Practical Guide
GPG often feels intimidating, yet a few good habits turn it into everyday protection: signed commits, safely managed keys, and verifiable releases. This seven-part series walks from the basic identity problem to enforcing verified commits in CI.
What You’ll Learn
- Part 1: The Author Identity Problem - Why Git authorship can be forged, and public/private key cryptography in plain language
- Part 2: Setting Up GPG and Automatic Commit Signing - Generating strong keys and configuring Git
- Part 3: Master Keys, Subkeys and Key Rotation - Daily signing without risking your primary key
- Part 4: Disaster Recovery - Revocation certificates and safe key backups
- Part 5: Signing Releases and Enforcing Verified Commits - Supply chain security for open-source and Python projects
- Part 6 (Bonus): Signing and Encrypting Email with PGP - Reusing your keys for email
- Part 7: Inside a Signed Git Commit - An advanced look at objects, signatures and attacks
- Part 6 (Bonus): Signing and Encrypting Email with PGP - Reusing your keys for email
- Part 7: Inside a Signed Git Commit - An advanced look at objects, signatures and attacks
Series Progress
0 of 7 posts published
All Posts in This Series
Part 1: The Author Identity Problem: Why Git Commits Can Be ForgedComing SoonAnyone can set user.name and user.email in Git, and timestamps are just text. This first part shows how easily a commit can be forged and explains public and private key cryptography in plain language, so signing makes sense before we set anything up. This post is currently being written and will be published soon. |
|
Part 2: Setting Up GPG and Automatic Git Commit SigningComing SoonInstall GPG, generate a strong Ed25519 or 4096-bit RSA key, and configure Git to sign every commit automatically. I also show how to add the public key to GitHub and get the green Verified badge. This post is currently being written and will be published soon. |
|
Part 3: Master Keys, Subkeys and Key Rotation in GPGComing SoonWhy your primary key should stay offline, how to create a dedicated signing subkey, and how to set and extend expiry dates so a leaked daily key is a small problem, not a disaster. This post is currently being written and will be published soon. |
|
Part 4: GPG Disaster Recovery: Revocation Certificates and Key BackupsComing SoonLost laptop, forgotten passphrase, leaked key: generate a revocation certificate in advance, back up your keys safely with a password manager and offline storage, and practise restoring them. This post is currently being written and will be published soon. |
|
Part 5: Signing Releases and Enforcing Verified Commits in CIComing SoonSign release tags and Python package artifacts, and enforce signed commits with GitHub branch protection and CI checks, so your software supply chain can be verified end to end. This post is currently being written and will be published soon. |
|
Part 6: Bonus: Signing and Encrypting Email with PGPComing SoonBonus material: use the PGP skills from this series for email. Add an encryption subkey, exchange public keys, and sign and encrypt messages in a mail client. This post is currently being written and will be published soon. |
|
Part 7: Inside a Signed Git Commit: Objects, Signatures and AttacksComing SoonAn advanced look under the hood: how Git stores a commit signature in the gpgsig header, what exactly gets signed, how verification and trust work, and which attacks signing does and does not stop. This post is currently being written and will be published soon. |
|
Getting Started
This series is coming soon. The first post introduces the foundations.
Who Is This Series For?
- Developers who want their commits and releases to be verifiably theirs
- Open-source maintainers who need to trust contributions and publish signed releases
- Technical writers and creators who care about digital authenticity and ownership