[DISCUSS] Commit Signature Verification
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 62/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- git
調査の方向性
まずリポジトリルートの CONTRIBUTING.md とプルリクエストテンプレートから始めましょう。この提案では、署名に関するノートの対象として両方が挙げられています。短い「how to sign commits」のセットアップガイド用に docs/ やコントリビューターガイドのディレクトリが存在するか確認してください。完成条件は次のとおりです: 貢献ドキュメントで GPG/SSH signing が推奨(必須ではない)と記載されていること、親切なセットアップガイドが追加されていること、PR のチェックリストがそれを参照していること。なお、これはコメントがまだない [DISCUSS] 件です — 大きなことを書き始める前にメンテナーの賛同を確認してください。
索引モデルが issue の本文から書いたものです。
説明
Summary
To improve trust, traceability, and review quality across our community, we encourage contributors to sign their commits with GPG, SSH, or S/MIME.
Commit signature verification helps confirm that a commit was really created by the stated author and has not been altered. GitHub’s documentation explains the verification process in detail:
This discussion is not meant to add unnecessary friction for contributors. Rather, it is intended to promote a small but meaningful security practice that can make our project history easier to trust and audit.
Proposal
- Encourage signed commits for contributors and maintainers.
- Mention this practice in the contribution guidelines and related documentation.
- Provide a short, friendly setup guide for contributors who want to enable signing.
Rationale
A signed commits are useful for:
- confirming commit authorship
- improving confidence in project history
- supporting future review and troubleshooting
- reinforcing good security hygiene in the community
Friendly Guidance for Contributors
We welcome contributors of all backgrounds. If you have not used GPG signing before, a simple setup guide and a few clear examples should be enough to get started.
If this would be helpful, we can also prepare:
- a short “how to sign commits” guide
- a note in
CONTRIBUTING.md - a reminder in the PR template or contributor checklist
Your feedback and ideas are highly appreciated.
Thanks!
- 主要言語
- Java
- スター
- 6.2k
- フォーク
- 535
- 平均マージ
- 11時間 19分
- マージ済み PR(30日)
- 21
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
apache/fesod のほかの issue
-
fesod-shaded jar: NOTICE/LICENSE missing Spring and ASM (OW2) copyright lines対応中かも @skytin1004 が 4 日前に担当しました。 オープン
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
apache/fesod#1172 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
[Bug] Default date detection rejects yyyy/MM/dd while accepting slash date-times対応中かも @Aias00 が 7 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
[Bug] BigDecimalBooleanConverter treats scaled one values as false対応中かも @Aias00 が 7 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
apache/fesod#1150 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
[Bug] Writing multiple sheets to CSV silently drops unflushed rows対応中かも @Aias00 が 7 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
[Bug] Hyperlink with a # part is read back without its target対応中かも @nkuprins が 11 日前に担当しました。 オープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
jenkinsci/ec2-plugin#2041 ·
-
L: github:actions L: php:composer
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
dependabot/dependabot-core#16493 ·
メンテナーはふだん 1 日以内に返信
-
SHOW EDIT of a subclass for an object of its superclass: the form fails to open with AssertionErrorオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 78/100
FlashyReese/sodium-extra#608 ·