Hi all,

As someone who regularly interacts with ITs, I think this is indeed a step in the right direction to make QGIS more trusty. And it will also serve as a good benchmark for contributions made in "vibe-coding" mode.

What are the next steps? Will there be a QEP to amend the contributor guidelines, and what is the implementation timeline?

Regards,
Julien

Le 25/06/2026 à 08:54, Régis Haubourg via QGIS-Developer a écrit :
Hi all, agreed.

On the security and PSC channel, I already spotted some IT departments asking for our current security practices. And one of them specifically asked for signed commits.
I guess this will only increase.

As this is a quick win for us, +1 ( I feel qualified to vote here, handling a good part of the security processes)

Cheers

Régis

Bien cordialement,
Régis Haubourg

On 25/06/2026 07:59, Nyall Dawson via QGIS-Developer wrote:
Basically to start locking down our repo. I think it's a relatively small step that would help establish more trust in our development process, especially by big business.
_______________________________________________
QGIS-Developer mailing list
[email protected]
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer
--
Oslandia <https://oslandia.com/?utm_source=email&utm_campaign=signature_oslandia&utm_medium=email> - Livre blanc pour migrer/hybrider son SIG <https://oslandia.com/livre-blanc-migration-sig-opensource/?utm_source=email&utm_campaign=signature_oslandia&utm_medium=email>

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
QGIS-Developer mailing list
[email protected]
List info: https://lists.osgeo.org/mailman/listinfo/qgis-developer
Unsubscribe: https://lists.osgeo.org/mailman/listinfo/qgis-developer

Reply via email to