Why we should consider verified commits #3812
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.

Description
This PR is a proof of concept: DO NOT MERGE.
At the moment, we don't enforce verification that whose who author a commit are actually who they say they are. For example, this PR has 4 commits:
The last commit was achieved by generating and adding a GPG key to my account and setting my git client to use that key. No one but me can have a "verified" commit.
I believe this can easily be done in Github Desktop as well.
I suggest that we consider asking core contributors to set it up. Here is some additional information about "verified" commits, including a new feature called "vigilant mode", where you're required to sign your commits.
Related Screenshot(s)