Got it, thank you. I'd love it if we could make sure it works both
ways--locally and on github--so we're not locked into the way github does
this. I suggest improving the script so it can handle both kinds of
signatures. I mean, assuming this is possible. If not, let's use the method
that for sure works both locally and on github (signing commits with
pgp/gpg only)--as (I think) gpg signatures are used throughout the ASF.

If we need public keys to make it work locally, we could use the github API
endpoints for fetching user public SSH and GPG/PGP keys, then [cache and]
use them locally.

As for when to run the check, do you mean it would run before a reviewer
approves workflows to run? That sounds great to me.

Reply via email to