Tweak information regarding the GitHub GPG key #6615
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Why:
Following the discussion #6444 I had with @felicitymay, this pull request includes changes to information regarding GPG verification that have been discussed in that thread.
What's being changed:
The paragraph with information on GitHub's key that is used to sign web commits has been slightly rearranged to improve readability, and the full fingerprint of the key has been added, which enables everybody to directly verify that the key they downloaded is indeed correct.
Check off the following:
I think that for security reasons, before merging in this pull request, it is necessary that at least one, but preferably more GitHub employees check the key fingerprint and explicitly write an approval in this pull request stating that the fingerprint is indeed correct.