v1.7.3
Verified commits from agent runs
v1.7.3 signs what an agent run commits.
Verified, and still in your name
A run's commits used to arrive on GitHub unsigned, marked unverified under the name of the person
who asked. They are now signed by siGit Code. The person who asked stays the author. The committer
is siGit Code, named with its release the same way as in the Co-Authored-By trailer, for example
siGit Code v1.6.1-headless. GitHub verifies a commit by its committer, so the commit shows as
verified.
Where the key is
The signing key stays on sigit.si. The job on the runner sends each commit to be signed and gets a signature back; neither the job nor the agent ever holds the key. sigit.si signs only a commit authored as the run's requester and committed as siGit Code.
The author of every commit in a run is now set to the person who asked, whatever the agent configured in its working copy.
When a commit cannot be signed
The run still delivers its work. The commits are pushed unsigned, as before this release, and the job log says so.
Release masters: @setoelkahfi and @sigit.