Repository navigation
Support gpg commit signing #1018
Description
Activity
Started taking a look at libgit2, and it looks like they have only recently added support for this...
Looks like libgit2 is starting to work in support for commit signing. libgit2/libgit2#3673
It looks like that function is enabled in
masterright now so feel free to poke around and see how it works.We could probably write a helper method in
lib/commit.jsto make the API a little better but we definitely want some tests to confirm our bindings work so that's the best place to start IMO.I had found the commit, but didn't notice that PR with the discussion, which was helpful, thanks. I hope they may reconsider their API to be a bit easier to use...
How frequently does nodegit take in new versions of libgit2?
Second question: would nodegit also be averse to having the ability to support gpg signing? Or would you be inclined to stick closer with being javascript bindings for libgit2 and just expose the same API they do?
How frequently does nodegit take in new versions of libgit2?
HIstorically we've been slow to update libgit2 but hopefully with #1017 it'll make it a bit easier to handle that.
Second question: would nodegit also be averse to having the ability to support gpg signing? Or would you be inclined to stick closer with being javascript bindings for libgit2 and just expose the same API they do?
Normally what we do in this situation is to do both. We automatically generate the wrappers for the public libgit2 functions and if we need to provide a better API or some other convenience function we'll throw that into
lib/<whatever>.js.For more complicated things that are out of scope there is always making a new repo that leverages NodeGit to do what you need (i.e. https://github.com/smith-kyle/nodegit-flow).
I think that something like gpg signing is out of scope for this repo but would be ideal for something like a
nodegit-gpg-signingrepo/package.This is closer now with #1041
@johnhaley81 could you provide an example for
Commit.createWithSignatureand how to commit toHEADwith it?Where can I find the source code?
@johnhaley81 Any updates on gpg signing?
@oscar-b I haven't been doing much with NodeGit lately. /cc @implausible @Mr-Wallet are you guys bringing in gpg signing?
We're not... not bringing in gpg signing... 😅
@Mr-Wallet looking forward to it 👏🏻
<_< >_> 😅 💦
was this implemented? if not, are there any updates on when is this planned?
I'm not making any promises, but my team has scheduled time for this - we would like this done before the end of Winter.
Reacted by Neil Kalman, Matt Hauck, Hendrik Minniear Rombach, Kyle Simpson, Oscar Bolmsten, Dan Butvinik and Gamunu BalagallaReacted by Oscar Bolmsten and Gamunu BalagallaReacted by Oscar Bolmsten28 remaining items
- added a commit that references this issue
on Jan 16, 2019 woohoo this just landed in #1448 !!
I've got an implementation for signing commits using openpgp setup as a separate library for reference if anyone on this thread is interested.
https://github.com/dabutvin/pgp-commit
After the next nodegit release I can push to npm
Reacted by Vladimir Jimenez, Hendrik Minniear Rombach, Cameron Tacklind and Neil KalmanWe are missing rebase support for commit signing still. So I am going to re-open this as it's Almost There™
Hi, is this still active?
Rebase commit signing is available in the 0.25.0 alpha.
I recently tried to use
createCommitWithSignaturebut I am getting this error:Error: Repository.prototype.createCommitWithSignature threw with error code undefined
at /home/pawel/workspace/arc/api-components-apps/ci-app/node_modules/nodegit/dist/repository.js:597:23
at async GitSourceControl.createCommit (github/git-source-control.js:252:12)The implementation is like this:
const author = this._createSignature(); const committer = this._createSignature(); return await repo.createCommitWithSignature(branch, author, committer, message, oid, parents, this._onSignature.bind(this));
where
_createSignature()is something likereturn Git.Signature.now(name, email);with existing values. The_onSignature: generates (I think) valid signature that looks like this:'-----BEGIN PGP SIGNATURE-----\r\n' + 'Version: OpenPGP.js v4.6.2\r\n' + 'Comment: https://openpgpjs.org\r\n' + '\r\n' + 'wsFcBAABCgAGBQJdxR12AAoJEK4/n/A8X2x7mfwP/R8n9cgyh2yKCpMoXrpO\r\n' + ... (removed) 'yRj2\r\n' + '=K/v+\r\n' + '-----END PGP SIGNATURE-----\r\n'
I am not sure how to debug this to produce more information. Any help? :)
@jarrodek the first thing that jumps out to me about your signature is the
\r\nline breaks
I am pretty sure they have to be\nCan you share your
_onSignatureimplementation?I've got a reference implementation using openpgp over here if you want to check it out: https://github.com/dabutvin/pgp-commit/blob/master/index.js
So the implementation is here: https://github.com/advanced-rest-client/api-components-apps/blob/818c19ecf2e99ddaad813d85d7341be2aac30d56/ci-app/github/git-source-control.js#L192
I will take a look into your reference @dabutvin and will see if it helps
I think the return value of your method should be an object, not just the signature
return { code: Git.Error.CODE.OK, field: 'gpgsig', signedData: signed.signature }Reacted by Marcin Cieślak and Paweł Uchida-PsztyćError: Repository.prototype.createCommitWithSignature threw with error code undefined
at /home/pawel/workspace/arc/api-components-apps/ci-app/node_modules/nodegit/dist/repository.js:597:23Which version exactly are you using?
@dabutvin this seems to work. Thank you.
I took a liberty of creating this PR that adds an example of how to create signed commits.
I have also added this gist which is basically the same: https://gist.github.com/jarrodek/218f0469691ab12b4254db2ff191c9f5Reacted by Marcin Cieślak
nodegit does not appear to have support yet for gpg commit signing. Perhaps I have missed it in the documentation, but there does not appear to be support for this quite yet. Do you have plans to support it some time soon? If not, would you be willing to specify the API you would like to see so others could contribute?
Thanks.