Ch. 16 · Git & CI/CD

Git Signed Commits and Tags

Sign commits and tags, verify signatures, and enforce them to prove who authored a change.

~2 min readadvancedupdated Oct 5, 2026

Commit author and email are just text, so anyone can set them. A signature proves the commit was made by someone who holds a specific key, which is the difference between a claimed identity and a verified one. This matters for release integrity and supply chain.

Before you start

You should understand GPG or SSH keys and basic commits. This article covers signing and verifying.

Step-by-step walkthrough

Step 1: Configure a signing key

Set user.signingkey and sign with -S, or enable commit.gpgsign to sign every commit. Git supports GPG and, in recent versions, SSH keys for signing. The commit records the signature, which is verified against the key.

Step 2: Sign tags too

Release tags should be signed as well, since they are the reference to what shipped. git tag -s creates a signed annotated tag. A signed tag and signed commits together give a verifiable release chain.

Step 3: Verify and enforce

git log --show-signature and git verify-commit check signatures against trusted keys. Platforms can require signed commits on protected branches, which rejects unsigned or unverifiable commits. Enforcement is what makes signing meaningful, since an unverified signature proves nothing.

Worked scenario

The commit is signed and the signature verified.

git config user.signingkey <key-id>
git commit -S -m "Release fix"
git log --show-signature -1
Terminal

Walk through the example

-S signs the commit with the configured key, and git log --show-signature shows whether the signature is valid and trusted. If the signer’s key is not trusted on this machine, the signature may verify cryptographically but not be trusted. Enforcement on the server closes that gap.

Common mistake

Signing commits but never verifying them, so an unsigned or forged commit slips through. Another is a key that expired or is not trusted on the verifier, which makes valid signatures report as untrusted.

Verify the behavior

Sign a commit and confirm git verify-commit reports a good signature. Commit unsigned and confirm verification fails or is absent. Enable required signed commits and confirm the server rejects an unsigned push.

Interview exercise

Why is a verified signature more meaningful than a commit’s author field?

Answer and reasoning

The author field is free text that anyone can set to any name and email. A signature is cryptographic: it proves the commit was created by a holder of the private key. Verification against a trusted key therefore establishes identity in a way the author field cannot.

Continue learning

Compare supply chain in CI required checks and releases in Release versioning. Read the Git signing documentation and try the Git interview questions.

More in Git & CI/CD

read ✓Git & CI/CD · easy

Git Detached HEAD

What a detached HEAD is, when it happens, and how to keep commits made in that state.

~2 min readread →
read ✓Git & CI/CD · mid

Git Hooks and Local Automation

Automate checks with client and server hooks, share them through a framework, and enforce the same rules in CI where they cannot be bypassed.

~2 min readread →
read ✓Git & CI/CD · hard

Git LFS for Large Files

Track large binaries with Git LFS, keep pointer files in the repository, and plan for LFS storage and access.

~2 min readread →
esc