this post was submitted on 24 Jun 2025
6 points (100.0% liked)

Free and Open Source Software

19503 readers
21 users here now

If it's free and open source and it's also software, it can be discussed here. Subcommunity of Technology.


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS
 

Alternative to GPG

top 6 comments
sorted by: hot top controversial new old
[–] [email protected] 2 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

You can sign git commits using SSH keys, including the one you use to connect to GitHub/GitLab/Codeberg. These sites also support verifying the signature.

[–] [email protected] 2 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

Combine that with Bitwarden running as the SSH Agent [1] and you've got yourself a decent, secure way to sign commits, etc.

[1] https://bitwarden.com/help/ssh-agent/

[–] [email protected] 0 points 2 weeks ago (1 children)

Or 1password if that's your bag, I use 1password at work and bitwarden at home

[–] [email protected] 2 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

Wrong community? Or shill?

bitwarden vs 1password

And that's not the only difference that - in my humble opinion - makes bitwarden stand out sky high against this proprietary SAAS shit.

[–] [email protected] 0 points 2 weeks ago (1 children)

was just pointing out that 1password has an SSH agent, not that you should use it.

I would always recommend bitwarden, as its so cheap or free if you self host it. also vaultwarden is the lighter option

[–] [email protected] 4 points 2 weeks ago

At the very least you should proactively point out that you're recommending closed source, proprietary and paid software on a FOSS community, in the future.

Especially with password managers the SAAS closed source part is extremely relevant. I'd never entrust mine to that, let alone recommend it to others. Linux version with integrated ssh agent be damned.