From ee45ed9adbd6f9fa1299a04eda27e9bf43118dc0 Mon Sep 17 00:00:00 2001 From: "@matrixfurry.com" Date: Fri, 17 Oct 2025 03:02:21 -0500 Subject: [PATCH] Trust Tangled profiles Signed-off-by: @matrixfurry.com --- SECURITY.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index eeb0a03..dfd039c 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -15,6 +15,8 @@ SSH signing is preferred over PGP signing. To enable signature verification, add your public key to your Tangled profile, and optionally the `.allowed_signers` file in the project's repo. +Tangled profiles should be trusted over the repo's copy, excluding revoked keys. + ## Setup Replace `` with the SSH key or keyfile you'd like to use (eg. `~/.ssh/id_ed25519`). -- 2.51.2