16. OpenPGP Signed Commits

OpenPGP signatures can be used at commit time to securely record the author of a change using public key encryption and at checkout time to verify the author of the revision being checked out is trusted.

See Global options and The connection method for more.

WARNING: Due to the sensitive nature of OpenPGP implementations, if you intend to employ CVS commit signatures as a security precaution, it is recommended that you make sure you are using an OpenPGP implementation with all the available security fixes. Check with the vendor of your OpenPGP implementation for information on its latest version.

