CodeFloe now signs the commits it creates itself with its own SSH key. This makes branch protection with “Require signed commits” work end to end: pull requests into protected branches can be merged straight from the web UI while every commit on the branch stays verified.
The instance signs:
- merge commits and squash commits created when merging a pull request,
- commits made in the web editor,
- the first commit of a new repository.
These commits are credited to the CodeFloe organization as committer and signer, and you stay the author:
The instance only signs a merge when the person merging has an SSH or GPG key on their account and two-factor authentication enabled. The latest commit on the target branch and every commit in the pull request must also be verified. The rebase merge styles rewrite commits without re-signing them, so use “Create merge commit” or “Create squash commit” on protected branches.
The public key is available at https://codefloe.com/api/v1/signing-key.ssh (fingerprint SHA256:PKT+oTn3Be7QgSZOB/sIKe5wW7rTFdekSZbuEMYGS0E). The commit signing docs explain how to verify these signatures locally and what to check if a merge doesn’t get signed.
Thanks to @wcornish for suggesting this!
