git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: upstreaming https://github.com/cgwalters/git-evtag ?

From
Santiago Torres <santiago@nyu.edu>
Date
Jan 8, 2018, 20:51 UTC
Message-ID
<20180108205138.jak7ahdppotgcckz@LykOS.localdomain>
In-Reply-To
<1515444153.3249266.1228432904.51A92479@webmail.messagingengine.com>

Yeah, I see where you're coming from. I don't think push certificates have caught on yet...

You can read on them on [1], and also under the Documentation/git-push:147.

There's also another PR trying to make a sample hook for signed pushes on [2].

The basic idea is to push a signed data structure with relevant git reference information as a git object to avoid a server/mitm from moving references around.

Cheers! -Santiago.

[1] https://public-inbox.org/git/1408485987-3590-1-git-send-email-gitster@pobox.com/ [2] https://public-inbox.org/git/20171202091248.6037-1-root@shikherverma.com/

On Mon, Jan 08, 2018 at 03:42:33PM -0500, Colin Walters wrote:
Show 13 quoted lines
> 
> 
> On Mon, Jan 8, 2018, at 3:40 PM, Santiago Torres wrote:
> > Hi,
> > 
> > I personally like the idea of git-evtags, but I feel that they could be
> > made so that push certificates (and being hash-algorithm agnostic)
> > should provide the same functionality with less code.
> 
> What's a "push certificate"?  (I really tried to find it in Google,
> even going to page 4 where one can start to see tumbleweeds
> going by... I'm fairly certain you're not talking about something related
> to iOS notifications) 
Previous: Colin WaltersNext: Stefan Beller
Message 5 of 11 in “upstreaming https://github.com/cgwalters/git-evtag ?”
  1. Colin WaltersJan 8, 2018
  2. Johannes SchindelinJan 8, 2018
  3. Santiago TorresJan 8, 2018
  4. Colin WaltersJan 8, 2018
  5. Santiago TorresJan 8, 2018
  6. Stefan BellerJan 8, 2018
  7. Santiago TorresJan 8, 2018
  8. Colin WaltersJan 9, 2018
  9. Santiago TorresJan 9, 2018
  10. Jonathan NiederJan 9, 2018
  11. Santiago TorresJan 10, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.