Hi all,As someone who regularly interacts with ITs, I think this is indeed a step in the right direction to make QGIS more trusty. And it will also serve as a good benchmark for contributions made in "vibe-coding" mode.
What are the next steps? Will there be a QEP to amend the contributor guidelines, and what is the implementation timeline?
Regards, Julien Le 25/06/2026 à 08:54, Régis Haubourg via QGIS-Developer a écrit :
Hi all, agreed.On the security and PSC channel, I already spotted some IT departments asking for our current security practices. And one of them specifically asked for signed commits.I guess this will only increase.As this is a quick win for us, +1 ( I feel qualified to vote here, handling a good part of the security processes)Cheers Régis Bien cordialement, Régis Haubourg On 25/06/2026 07:59, Nyall Dawson via QGIS-Developer wrote:Basically to start locking down our repo. I think it's a relatively small step that would help establish more trust in our development process, especially by big business._______________________________________________ QGIS-Developer mailing list [email protected] List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
--Oslandia <https://oslandia.com/?utm_source=email&utm_campaign=signature_oslandia&utm_medium=email> - Livre blanc pour migrer/hybrider son SIG <https://oslandia.com/livre-blanc-migration-sig-opensource/?utm_source=email&utm_campaign=signature_oslandia&utm_medium=email>
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ QGIS-Developer mailing list [email protected] List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
