{"id":21082840,"url":"https://github.com/jxareas/sign-with-gpg","last_synced_at":"2026-04-09T08:53:45.516Z","repository":{"id":129679881,"uuid":"580188663","full_name":"jxareas/Sign-with-GPG","owner":"jxareas","description":"Learn how to easily sign your commits with GPG Cryptographic Keys on MacOS \u0026 Windows.","archived":false,"fork":false,"pushed_at":"2023-04-11T05:38:31.000Z","size":12,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-01-20T23:47:05.818Z","etag":null,"topics":["commit-signing","cryptography","git","gpg","learn","macos","windows"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"cc0-1.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jxareas.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-12-19T23:47:34.000Z","updated_at":"2023-04-11T05:51:03.000Z","dependencies_parsed_at":null,"dependency_job_id":"f4d9ea9a-fee3-4730-b415-fe1fae79eb91","html_url":"https://github.com/jxareas/Sign-with-GPG","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jxareas%2FSign-with-GPG","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jxareas%2FSign-with-GPG/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jxareas%2FSign-with-GPG/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jxareas%2FSign-with-GPG/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jxareas","download_url":"https://codeload.github.com/jxareas/Sign-with-GPG/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243526855,"owners_count":20305112,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["commit-signing","cryptography","git","gpg","learn","macos","windows"],"created_at":"2024-11-19T20:15:26.236Z","updated_at":"2025-12-28T09:27:43.206Z","avatar_url":"https://github.com/jxareas.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# Sign your Commits with GPG\n\nThis repository provides simple intructions on how to sign your Git commits locally using GPG, in both [MacOS](./macos/README.md) and [Windows](./windows/README.md) Environments.\n\n## Why use GPG signatures?\n\nCommit signature verification allows you to sign commits and tags locally, to give other people confidence about the origin of a change you have made. If a commit or tag has a GPG, SSH, or S/MIME signature that is cryptographically verifiable, GitHub marks the commit or tag \"Verified\" or \"Partially verified.\"\n\nFor most individual users, GPG or SSH will be the best choice for signing commits. S/MIME signatures are usually required in the context of a larger organization. SSH signatures are the simplest to generate. You can even upload your existing authentication key to GitHub to also use as a signing key. Generating a GPG signing key is more involved than generating an SSH key, but GPG has features that SSH does not.\n\nA GPG key can expire or be revoked when no longer used. GitHub shows commits that were signed with such a key as \"Verified\" unless the key was marked as compromised. SSH keys don't have this capability.","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjxareas%2Fsign-with-gpg","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjxareas%2Fsign-with-gpg","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjxareas%2Fsign-with-gpg/lists"}