git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Is the sha256 object format experimental or not?

From
Ddwh@linuxprogrammer.org <dwh@linuxprogrammer.org>
Date
May 14, 2021, 17:39 UTC
Message-ID
<20210514173909.GA16542@localhost>
In-Reply-To
<20210514134501.3vzgqdfwwejafkq7@meerkat.local>
On 14.05.2021 09:45, Konstantin Ryabitsev wrote:
>As you know, this is my third attempt at getting patch attestation off the
>ground. 
Yes, I've been following. It's been a long road.
>I'm hoping that this version resolves the downsides of the previous two
>attempts by both being dumb and simple and by only requiring a simple one-time
>setup (via the sendemail-validate hook) with no further changes to the usual
>git-send-email workflow after that.

I'm very interested in whether this one works. You and I are completely aligned on this. I don't think I'm paying enough attention to the emailed patch attestations as you have. I think I understand the requirements but maybe not all of them. Do you have any threads on public-inbox where you discuss them? I want to make sure that what I'm doing doesn't undermine anything you're trying to do. The end goal is to have an air-tight provenance on all contributions and accountable/audtiable software supply chain. We're all working towards that.

>I've not yet widely promoted this, as patatt is a very new project, but I'm
>hoping to start reaching out to people to trial it out in the next few weeks.
Hopefully this approach strikes the right balance.

Cheers! Dave

Previous: Konstantin RyabitsevNext: Junio C Hamano
Message 14 of 19 in “Preserving the ability to have both SHA1 and SHA256 signatures”
  1. dwh@linuxprogrammer.orgMay 8, 2021
  2. Christian CouderMay 8, 2021
  3. Junio C HamanoMay 8, 2021
  4. Felipe ContrerasMay 8, 2021
  5. Stefan MochMay 8, 2021
  6. Junio C HamanoMay 8, 2021
  7. brian m. carlsonMay 9, 2021
  8. Is the sha256 object format experimental or not?Ævar Arnfjörð Bjarmason, May 10, 2021
  9. brian m. carlsonMay 10, 2021
  10. dwh@linuxprogrammer.orgMay 13, 2021
  11. Konstantin RyabitsevMay 13, 2021
  12. dwh@linuxprogrammer.orgMay 13, 2021
  13. Konstantin RyabitsevMay 14, 2021
  14. dwh@linuxprogrammer.orgMay 14, 2021
  15. Junio C HamanoMay 13, 2021
  16. dwh@linuxprogrammer.orgMay 13, 2021
  17. Ævar Arnfjörð BjarmasonMay 14, 2021
  18. dwh@linuxprogrammer.orgMay 14, 2021
  19. Jonathan NiederMay 18, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.