Gitar’s Public GPG Key
Use the following public key to verify commits signed by Gitar:Public GPG Key (click to expand)
Public GPG Key (click to expand)
This key is also available on GitHub for automated retrieval.
Verifying Commits Locally
Two commands, once you have the key above. Save the public key above to a file, for examplegitar.gpg, and import it:
Good signature from "Gitar <...>" in the output.
Verified badge, by platform
Gitar signs on every platform. Whether the platform then shows a Verified badge depends on where its key is registered.
If a commit on GitHub or GitLab has no badge, confirm that the commit’s author email matches the email on Gitar’s GPG key.