Tag
commit-signing
Safeguard articles tagged "commit-signing" — guides, analysis, and best practices for software supply chain and application security.
3 articles
Open Source Security
Contributing to open source securely: a guide for new maintainers and PR authors
It took roughly two years of trusted commits before the xz-utils backdoor shipped. Here's how new contributors avoid becoming the next weak link.
Jul 12, 20267 min read
Software Supply Chain Security
How to set up signed commits with GPG
A step-by-step guide to set up GPG signed commits in Git: generate a key, configure Git, publish it to GitHub, verify signatures, and fix common errors.
Feb 17, 20267 min read
AI Security
How to Set Your Git Username and Email (and Why It Matters for Security)
Your Git username and email stamp every commit you make. Here is how to configure them correctly across global and per-repo scopes, and why they matter for trust and audit.
Feb 4, 20266 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.