FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Support gpg commit signing · Issue #1018 · nodegit/nodegit · GitHub

Repository navigation

Support gpg commit signing #1018

Description

nodegit does not appear to have support yet for gpg commit signing. Perhaps I have missed it in the documentation, but there does not appear to be support for this quite yet. Do you have plans to support it some time soon? If not, would you be willing to specify the API you would like to see so others could contribute?

Thanks.

Activity

  1. matthauck commented on Apr 30, 2016

    Author

    Started taking a look at libgit2, and it looks like they have only recently added support for this...

  2. johnhaley81 commented on Apr 30, 2016

    Collaborator

    Looks like libgit2 is starting to work in support for commit signing. libgit2/libgit2#3673

    It looks like that function is enabled in master right now so feel free to poke around and see how it works.

    We could probably write a helper method in lib/commit.js to make the API a little better but we definitely want some tests to confirm our bindings work so that's the best place to start IMO.

  3. matthauck commented on Apr 30, 2016

    Author

    I had found the commit, but didn't notice that PR with the discussion, which was helpful, thanks. I hope they may reconsider their API to be a bit easier to use...

    How frequently does nodegit take in new versions of libgit2?

  4. matthauck commented on Apr 30, 2016

    Author

    Second question: would nodegit also be averse to having the ability to support gpg signing? Or would you be inclined to stick closer with being javascript bindings for libgit2 and just expose the same API they do?

  5. johnhaley81 commented on Apr 30, 2016

    Collaborator

    How frequently does nodegit take in new versions of libgit2?

    HIstorically we've been slow to update libgit2 but hopefully with #1017 it'll make it a bit easier to handle that.

    Second question: would nodegit also be averse to having the ability to support gpg signing? Or would you be inclined to stick closer with being javascript bindings for libgit2 and just expose the same API they do?

    Normally what we do in this situation is to do both. We automatically generate the wrappers for the public libgit2 functions and if we need to provide a better API or some other convenience function we'll throw that into lib/<whatever>.js.

    For more complicated things that are out of scope there is always making a new repo that leverages NodeGit to do what you need (i.e. https://github.com/smith-kyle/nodegit-flow).

    I think that something like gpg signing is out of scope for this repo but would be ideal for something like a nodegit-gpg-signing repo/package.

  6. johnhaley81 commented on Jun 8, 2016

    Collaborator

    This is closer now with #1041

  7. andrewrynhard commented on Sep 3, 2016

    @johnhaley81 could you provide an example for Commit.createWithSignature and how to commit to HEAD with it?

  8. andrewrynhard commented on Sep 3, 2016

    Where can I find the source code?

  9. oscar-b commented on Aug 25, 2017

    @johnhaley81 Any updates on gpg signing?

  10. johnhaley81 commented on Aug 26, 2017

    Collaborator

    @oscar-b I haven't been doing much with NodeGit lately. /cc @implausible @Mr-Wallet are you guys bringing in gpg signing?

  11. Mr-Wallet commented on Aug 28, 2017

    Contributor

    We're not... not bringing in gpg signing... 😅

  12. oscar-b commented on Aug 29, 2017

    @Mr-Wallet looking forward to it 👏🏻

  13. Mr-Wallet commented on Aug 29, 2017

    Contributor

    <_< >_> 😅 💦

  14. thatkookooguy commented on Jan 22, 2018

    was this implemented? if not, are there any updates on when is this planned?

  15. Mr-Wallet commented on Jan 22, 2018

    Contributor

    I'm not making any promises, but my team has scheduled time for this - we would like this done before the end of Winter.

  16. 28 remaining items

  17. added a commit that references this issue on Jan 16, 2019
    cbe5d0b
  18. dabutvin commented on Jan 16, 2019

    Contributor

    woohoo this just landed in #1448 !!

    I've got an implementation for signing commits using openpgp setup as a separate library for reference if anyone on this thread is interested.

    https://github.com/dabutvin/pgp-commit

    After the next nodegit release I can push to npm

  19. implausible commented on Jan 16, 2019

    Member

    We are missing rebase support for commit signing still. So I am going to re-open this as it's Almost There™

  20. jarrodek commented on Jul 23, 2019

    Hi, is this still active?

  21. implausible commented on Jul 24, 2019

    Member

    Rebase commit signing is available in the 0.25.0 alpha.

  22. jarrodek commented on Nov 8, 2019

    I recently tried to use createCommitWithSignature but I am getting this error:

    Error: Repository.prototype.createCommitWithSignature threw with error code undefined
    at /home/pawel/workspace/arc/api-components-apps/ci-app/node_modules/nodegit/dist/repository.js:597:23
    at async GitSourceControl.createCommit (github/git-source-control.js:252:12)

    The implementation is like this:

    const author = this._createSignature();
    const committer = this._createSignature();
    return await repo.createCommitWithSignature(branch, author, committer, message, oid,
            parents, this._onSignature.bind(this));

    where _createSignature() is something like return Git.Signature.now(name, email); with existing values. The _onSignature: generates (I think) valid signature that looks like this:

    '-----BEGIN PGP SIGNATURE-----\r\n' +
        'Version: OpenPGP.js v4.6.2\r\n' +
        'Comment: https://openpgpjs.org\r\n' +
        '\r\n' +
        'wsFcBAABCgAGBQJdxR12AAoJEK4/n/A8X2x7mfwP/R8n9cgyh2yKCpMoXrpO\r\n' +
        ... (removed)
        'yRj2\r\n' +
        '=K/v+\r\n' +
        '-----END PGP SIGNATURE-----\r\n'

    I am not sure how to debug this to produce more information. Any help? :)

  23. dabutvin commented on Nov 8, 2019

    Contributor

    @jarrodek the first thing that jumps out to me about your signature is the \r\n line breaks
    I am pretty sure they have to be \n

    Can you share your _onSignature implementation?

    I've got a reference implementation using openpgp over here if you want to check it out: https://github.com/dabutvin/pgp-commit/blob/master/index.js

  24. jarrodek commented on Nov 8, 2019

  25. dabutvin commented on Nov 9, 2019

    Contributor

    I think the return value of your method should be an object, not just the signature

    return {
          code: Git.Error.CODE.OK,
          field: 'gpgsig',
          signedData: signed.signature
        }
    
  26. saper commented on Nov 9, 2019

    Collaborator

    Error: Repository.prototype.createCommitWithSignature threw with error code undefined
    at /home/pawel/workspace/arc/api-components-apps/ci-app/node_modules/nodegit/dist/repository.js:597:23

    Which version exactly are you using?

  27. jarrodek commented on Nov 9, 2019

    I am using nodegit version 0.26.2 and openpgp version 4.6.2 @saper
    I will try this @dabutvin

  28. jarrodek commented on Nov 9, 2019

    @dabutvin this seems to work. Thank you.

  29. jarrodek commented on Nov 9, 2019

    I took a liberty of creating this PR that adds an example of how to create signed commits.
    I have also added this gist which is basically the same: https://gist.github.com/jarrodek/218f0469691ab12b4254db2ff191c9f5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL