Change wording of PP2 PR9 to be less ambigious

Should you happily sign another developer's GPG key? If not, please explain the checks you will make before signing it.

The question is asking me to explain the checks I will make if I should not happily sign a key. But I should be happy about it. If am not happy about signing a developer's key I can just choose not to sign the key. Is the question implying that I should sign someone's key even when I do not wish to do so? :)

The question is about the checks one should perform before signing any GPG key. Whether they should do so happily or not is not really relevant here. This also leaves a lot of room for ambiguity.

So, I propose we change it to:

Should you promptly sign another developer's OpenPGP key as soon as you're requested to do so? If not, please explain the checks you will make before signing it.

I believe it does a relatively better job of conveying the actual intent of the question without it being too on the nose.

Should you promptly sign another developer's OpenPGP key as soon as you're requested to do so?

No, I should not.

If not, please explain the checks you will make before signing it.

Before signing, I would [...]


P.S. The commits will be squashed into one when merged.

Merge request reports

Loading