Re: Question about scm security holes

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 03/04/2010 06:03 PM, Avery Pennarun wrote:

...you can create a commit with
whatever committer/author names you want and then push them in.
Commits aren't GPG-signed, only tags are, so there are lots of ways to
forge a commit from someone else and mess up the audit log...

Thanks, that's the kind of reply I was hoping for.  Do you think there
should be a way to sign the commits themselves, at least as an option?

I certainly wouldn't bother, but OTOH nobody wants to steal my code :-/

Do you suppose the devs at Adobe carry the complete source repository
home on their laptops every night?  (Not if they use Perforce, of course,
but they might if they adopted git as their scm.)
--
To unsubscribe from this list: send the line "unsubscribe git" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Kernel Development]     [Gcc Help]     [IETF Annouce]     [DCCP]     [Netdev]     [Networking]     [Security]     [V4L]     [Bugtraq]     [Yosemite]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux SCSI]     [Fedora Users]