This is an archive page, kept for posterity. Head back to our homepage

Sign and verify code

With Fluidkeys, signing and verifying commits, tags, releases and binaries is simple. Your team can see that code changes really came from a trusted developer and not a compromised account.

Configure git to sign code

Fluidkeys configures gpg, git and Github to work together seamlessly.

Verify code with status checks

Use Fluidkeys status check to verify that code was signed by an authorized team member not just anyone.

Enforce signed code

For extra security, use Github branch protection to block unsigned code from entering the codebase.

Verify signatures locally

Verify signatures in the normal git log workflow. All the team's keys are download automatically, allowing offline verification.