Repository navigation
Signed Git Commits Guide
We are enforcing signed commits across CDS Notify repositories. A signed commit lets GitHub cryptographically verify it really came from you, shown as the green Verified badge on commits/PRs.
Reference docs from GitHub:
Note
You already have an SSH key. Everyone signs into GitHub via SSO using an SSH key for git auth already. Signing commits with that same key is the fastest path - GitHub just needs you to also register it as a Signing Key (separate from the Authentication Key use you already have). You do not need to generate a new key pair for this.
⭐ SSH is the preferred signing method for CDS Notify repos. It reuses the key you already have, has no agent/
pinentryheadaches, and is what the Set up SSH signing scenario below walks you through. GPG still works and is fully supported, but if you're choosing a method or want to simplify, choose SSH.
Run this once to find out:
git config --get commit.gpgsign
git config --get gpg.formatcommit.gpgsign |
gpg.format |
Scenario | What to do |
|---|---|---|---|
| blank | blank | A - Not signing at all | Jump to Set up SSH signing (recommended) |
true |
blank or openpgp
|
B - Already signing with GPG | Jump to Check your GPG setup |
true |
ssh |
C - Already signing with SSH | Jump to Verify your SSH setup |
✅ Recommended. You're not signing commits yet. Since you already have an SSH key for GitHub, reuse it - no GPG required.
Warning
GitHub separates Authentication and Signing permissions. You need to add your existing public key to GitHub under the Signing Key type.
- Copy your local public SSH key to your clipboard:
(If using an RSA key, replace with
pbcopy < ~/.ssh/id_ed25519.pub
~/.ssh/id_rsa.pub) - Go to GitHub.com → Settings → SSH and GPG keys.
- Click New SSH Key.
- Set Title to something identifiable (e.g.,
MacBook (Signing)). - Change the Key type dropdown from Authentication Key to Signing Key.
- Paste your key in the Key field and click Add SSH key.
- (If applicable) Click Configure SSO / Authorize next to the new key to authorize it for your organization.
Run these three commands in Terminal to tell Git to use your SSH key for signing:
# 1. Set Git signature format to SSH
git config --global gpg.format ssh
# 2. Point Git to your public SSH key
git config --global user.signingkey ~/.ssh/id_ed25519.pub
# 3. Enable automatic commit signing globally
git config --global commit.gpgsign trueThis prevents Git from throwing gpg.ssh.allowedSignersFile needs to be configured when checking local commit logs.
- Create an allowed signers file with your Git email and public SSH key:
echo "$(git config user.email) $(cat ~/.ssh/id_ed25519.pub)" >> ~/.ssh/allowed_signers
- Tell Git where to look for allowed signers:
git config --global gpg.ssh.allowedSignersFile ~/.ssh/allowed_signers
If you've already added the signing key to GitHub and just need to configure a local Mac in one go, paste this into Terminal:
git config --global gpg.format ssh && \
git config --global user.signingkey ~/.ssh/id_ed25519.pub && \
git config --global commit.gpgsign true && \
echo "$(git config user.email) $(cat ~/.ssh/id_ed25519.pub)" >> ~/.ssh/allowed_signers && \
git config --global gpg.ssh.allowedSignersFile ~/.ssh/allowed_signersYou're already using the recommended method (gpg.format = ssh) locally. The part people miss here is confirming the key is registered on GitHub specifically as a Signing Key, not just an Authentication Key - it's easy to have one without the other.
- First, you need to provide signing keys permissions to manage your public keys:
You will need to copy a confirmation code and paste it into a new browser's window once you hit
gh auth refresh -h github.com -s admin:ssh_signing_key
ENTER. - Check which SSH signing keys GitHub already has on file for you:
If this comes back empty, GitHub has no signing key for you yet, even if you use SSH to push/pull every day.
gh api user/ssh_signing_keys -q '.[].title' - If your key isn't listed, add it: copy your public key (
pbcopy < ~/.ssh/id_ed25519.pub), go to GitHub.com → Settings → SSH and GPG keys → New SSH key, and set Key type to Signing Key (see Scenario A, Step 1 for the full walkthrough).
Then continue to Test with an empty commit below.
You're already configured for GPG signing. Run this quick diagnostic before deciding whether to keep it.
1. Test GPG agent and passphrase prompt
echo "test" | gpg --clearsign-
Pass: Outputs
-----BEGIN PGP SIGNED MESSAGE-----(or prompts for your passphrase cleanly). -
Fail: Throws
gpg: signing failed: Inappropriate ioctl for deviceorno pinentry.
2. Verify Git is configured to auto-sign
git config --get commit.gpgsign
git config --get user.signingkey-
Pass:
commit.gpgsignreturnstrueanduser.signingkeyreturns a key ID (e.g.,3AA5C34371567BD2). - Fail: Either command returns blank.
3. Test an actual signed commit locally
git commit --allow-empty -m "test gpg signature"
git log -1 --show-signature-
Pass: Output shows
gpg: Good signature from... -
Fail: Output shows
gpg: double check your gpg installationor no signature info.
Verdict
- All 3 passed? Your GPG setup works, but SSH is still the preferred method for this org - see switching to SSH below, or continue to the GitHub check if you'd rather stick with GPG.
- Any failed? Don't bother troubleshooting
gpg-agentorpinentry- just switch to SSH signing, it takes under 2 minutes and reuses the SSH key you already have. See switching to SSH below.
Switching takes under 2 minutes and doesn't require removing your GPG key from GitHub - just follow Scenario A above. Once gpg.format is set to ssh, Git will sign new commits with your SSH key instead, regardless of any GPG key still on file.
A valid local signature is not enough - GitHub only shows Verified if it already has the matching public key. This is the step people most often miss.
- List your local GPG key ID (matches
user.signingkeyfrom above):gpg --list-secret-keys --keyid-format=long
- Check what GitHub already has on file: go to GitHub.com → Settings → SSH and GPG keys and look under GPG keys.
- If your key ID isn't listed there, export and add it:
Copy the full
gpg --armor --export <YOUR_KEY_ID>
-----BEGIN PGP PUBLIC KEY BLOCK-----output, then in GitHub click New GPG key and paste it in.
Then continue to Test with an empty commit.
Run an empty test commit locally:
git commit --allow-empty -m "test signed commit"
git log -1 --show-signature-
Local check: Output should say
Good "git" signature for...(SSH) orgpg: Good signature from...(GPG). - GitHub check: Push the commit to GitHub. Your commit log on GitHub.com will now show the green Verified badge.
Delete the test commit/branch once confirmed.
Once your team has confirmed their local setup works, repo admins can enforce this at the branch level: Settings → Branches → Branch protection rule → Require signed commits. This rejects any unsigned push outright instead of relying on after-the-fact audits.