Action Required: Signed Commits Mandatory for All Grafana Repositories

:locked_with_key: Signed commits will be required starting 22 June 2026

To help improve the security and integrity of our project, we now require all commits to have verified signatures.

All commits submitted to all Grafana repositories will need to have a valid signature in order to be merged.

Why are we making this change?

  • Verify that commits come from the person who authored them

  • Protect against impersonation and unauthorized changes

  • Improve the traceability and provenance of contributions

What do contributors need to do:

Before making your next contribution, please set up (just once) commit signing using either:

Unsigned commits will be rejected by the system and would have to be resubmitted when signed.

How can I check if my commits are signed?

On GitHub, signed commits will show a “Verified” badge.

Thanks for helping us keep the project secure and trustworthy for everyone who contributes! :grafana: :orange_heart:

1 Like