it's almost as if the entire notation regarding signed commits as a way of verifying authenticity is just a false premise.
-
@[email protected] @[email protected] I'm assuming in this case that the people who would notice such discrepancies would also be pulling from MIT or another trusted key server to verify the key is valid. I wouldn't notice this personally (unless someone pointed it out to me) because I don't usually pay attention to signed/unsigned commits
Copyright © 2025 NodeBB | Contributors