jj-sign
cryptographically signs Jujutsu revisions
TLDR
SYNOPSIS
jj sign [-r REVSETS] [--key KEY]
DESCRIPTION
jj sign rewrites the selected revisions so each carries a cryptographic signature. A commit signing backend must be configured (`gpg`, `gpgsm`, or `ssh`). Without a backend the command errors and points at the official commit-signing docs.Every selected revision is signed again, even if it is already signed by you. Descendants are rebased onto the rewritten commits. Commits whose author email is not yours still get signed; a warning is printed. Immutable revisions cannot be rewritten unless `--ignore-immutable` is passed.Automatic signing on later rewrites is controlled by `signing.behavior` (`drop`, `keep`, `own`, `force`), which is separate from this manual command.
PARAMETERS
-r, --revision REVSETS
Revisions to sign (repeatable; alias `--revisions`). If omitted, uses the `revsets.sign` setting (default: `reachable(@, mutable())`). Selected revisions are always re-signed.--key KEY
Signing key for this invocation. For GnuPG, anything `gpg -u` accepts. For SSH, a public key or path to a `.pub` file.
CONFIGURATION
Enable a backend and choose when rewritten commits are signed:
behavior = "own"
backend = "gpg"
# key = "4ED556E9729E000F"
behavior = "own"
backend = "ssh"
key = "~/.ssh/id_ed25519.pub"
sign = "reachable(@, mutable())"
INSTALL
CAVEATS
Subcommand of jj. Re-signing already-signed commits is intentional (hardware tokens will be prompted again). Signing someone else's commits is allowed but warned. Immutable history is skipped unless `--ignore-immutable`. Signatures on rewritten descendants follow `signing.behavior`, not this command.
SEE ALSO
jj(1), jj-unsign(1), jj-config(1), git-commit(1)
