LinuxCommandLibrary
GitHubF-DroidGoogle Play Store

jj-sign

cryptographically signs Jujutsu revisions

TLDR

Sign revisions in the default `revsets.sign` set (`reachable(@, mutable())`)
$ jj sign
copy
Sign a specific revision
$ jj sign -r [revset]
copy
Sign several revsets
$ jj sign -r [revset1] -r [revset2]
copy
Sign with an explicit key (overrides `signing.key`)
$ jj sign --key [key_id] -r [revset]
copy
Show cryptographic signatures in the log
$ jj log --config ui.show-cryptographic-signatures=true
copy

SYNOPSIS

jj sign [-r REVSETS] [--key KEY]

DESCRIPTION

jj sign rewrites the selected revisions so each carries a cryptographic signature. A commit signing backend must be configured (`gpg`, `gpgsm`, or `ssh`). Without a backend the command errors and points at the official commit-signing docs.Every selected revision is signed again, even if it is already signed by you. Descendants are rebased onto the rewritten commits. Commits whose author email is not yours still get signed; a warning is printed. Immutable revisions cannot be rewritten unless `--ignore-immutable` is passed.Automatic signing on later rewrites is controlled by `signing.behavior` (`drop`, `keep`, `own`, `force`), which is separate from this manual command.

PARAMETERS

-r, --revision REVSETS

Revisions to sign (repeatable; alias `--revisions`). If omitted, uses the `revsets.sign` setting (default: `reachable(@, mutable())`). Selected revisions are always re-signed.
--key KEY
Signing key for this invocation. For GnuPG, anything `gpg -u` accepts. For SSH, a public key or path to a `.pub` file.

CONFIGURATION

Enable a backend and choose when rewritten commits are signed:

$ [signing]
behavior = "own"
backend = "gpg"
# key = "4ED556E9729E000F"
copy
SSH example:
$ [signing]
behavior = "own"
backend = "ssh"
key = "~/.ssh/id_ed25519.pub"
copy
Default set signed by a bare `jj sign`:
$ [revsets]
sign = "reachable(@, mutable())"
copy
Show signatures in templates with `ui.show-cryptographic-signatures = true`.

INSTALL

sudo pacman -S jujutsu
copy
sudo apk add jujutsu
copy
sudo zypper install jujutsu
copy
brew install jujutsu
copy
nix profile install nixpkgs#jujutsu
copy

CAVEATS

Subcommand of jj. Re-signing already-signed commits is intentional (hardware tokens will be prompted again). Signing someone else's commits is allowed but warned. Immutable history is skipped unless `--ignore-immutable`. Signatures on rewritten descendants follow `signing.behavior`, not this command.

SEE ALSO

jj(1), jj-unsign(1), jj-config(1), git-commit(1)

RESOURCES

Copied to clipboard
Kai