Re: Question about scm security holes
- From
John Tapsell <johnflux@gmail.com>
- Date
- Mar 5, 2010, 03:00 UTC
- Message-ID
- <43d8ce651003041900x66000be4s9a15ab0cde3a0fe7@mail.gmail.com>
- In-Reply-To
- <32541b131003041803q9abf6baq4cf9ffcca990b51c@mail.gmail.com>
On 5 March 2010 02:03, Avery Pennarun <apenwarr@gmail.com> wrote:
> modified code would be a little more interesting. git makes this sort > of thing pretty much impossible to do without it being *noticeable* at > least. Traceable, not so much, because you can create a commit with > whatever committer/author names you want and then push them in.
Which is why you simply record the username of whoever pushed them in. This is what gitorious.org does etc.
John