)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"36fa97899ca9c33144bdde7e420169a92c5505f5","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"02973866_1b4ed6ab","updated":"2022-09-14 22:14:27.000000000","message":"\u003e If we\u0027re going to rely on this, would we expect all prospective contributors to the repository to sign their commits, and not approve their changes until they got it figured out? While the additional traceability is nice,  it seems like it would raise the complexity of contributing even more than we already have.\n\nNo, I don\u0027t see us relying on this or requiring this -- certainly not the intent.\n\nJust if people are choosing to sign their commits, we can keep a record of the key they are doing that with here.  I mean, it would be good to have everything signed *if* we ended up in a situation where we didn\u0027t trust what was on disk for some reason.  But even so, it seems that even having partially signed changes in that case at least reduces any potential audit footprint?\n\nIf it did become a required thing, I think it would have to be much more integrated into the workflow from gerrit, which it certainly isn\u0027t atm.","commit_id":"f489a07cc6fb81e7f9fd12e7378dd654b816f766"}]}
