Security Vulnerability: Faulty GPG Signature Checking

Greg Minshall minshall at acm.org
Mon Jun 18 17:39:16 CEST 2018


Ben,

> No. It only stops people from adding new commits who don't have your
> GPG key.

thanks (again).  one thing is that now "pass insert" requires inputting
your gpg key (in order to sign, presumably).  so, a very minor
annoyance.

cheers, Greg


More information about the Password-Store mailing list