[QGIS-Developer] Requiring signed commits?

Julien Moura (Oslandia) julien.moura at oslandia.com
Thu Jun 25 01:37:02 PDT 2026


Hi all,

As someone who regularly interacts with ITs, I think this is indeed a 
step in the right direction to make QGIS more trusty. And it will also 
serve as a good benchmark for contributions made in "vibe-coding" mode.

What are the next steps? Will there be a QEP to amend the contributor 
guidelines, and what is the implementation timeline?

Regards,
Julien

Le 25/06/2026 à 08:54, Régis Haubourg via QGIS-Developer a écrit :
> Hi all, agreed.
>
> On the security and PSC channel, I already spotted some IT departments 
> asking for our current security practices. And one of them 
> specifically asked for signed commits.
> I guess this will only increase.
>
> As this is a quick win for us, +1 ( I feel qualified to vote here, 
> handling a good part of the security processes)
>
> Cheers
>
> Régis
>
> Bien cordialement,
> Régis Haubourg
>
> On 25/06/2026 07:59, Nyall Dawson via QGIS-Developer wrote:
>> Basically to start locking down our repo. I think it's a relatively 
>> small step that would help establish more trust in our development 
>> process, especially by big business.
> _______________________________________________
> QGIS-Developer mailing list
> QGIS-Developer at lists.osgeo.org
> List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
> Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
-- 
Oslandia 
<https://oslandia.com/?utm_source=email&utm_campaign=signature_oslandia&utm_medium=email> 
- Livre blanc pour migrer/hybrider son SIG 
<https://oslandia.com/livre-blanc-migration-sig-opensource/?utm_source=email&utm_campaign=signature_oslandia&utm_medium=email>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://lists.osgeo.org/pipermail/qgis-developer/attachments/20260625/556d60f8/attachment.sig>


More information about the QGIS-Developer mailing list