git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Question about scm security holes

From
John Tapsell <johnflux@gmail.com>
Date
Mar 5, 2010, 04:07 UTC
Message-ID
<43d8ce651003042007o4e41e527j8f64c898e7492d70@mail.gmail.com>
In-Reply-To
<32541b131003041919u6a477b46s447a6aeb18f3b393@mail.gmail.com>
On 5 March 2010 03:19, Avery Pennarun <apenwarr@gmail.com> wrote:
Show 14 quoted lines
> On Thu, Mar 4, 2010 at 10:00 PM, John Tapsell <johnflux@gmail.com> wrote:
>> On 5 March 2010 02:03, Avery Pennarun <apenwarr@gmail.com> wrote:
>>> modified code would be a little more interesting.  git makes this sort
>>> of thing pretty much impossible to do without it being *noticeable* at
>>> least.  Traceable, not so much, because you can create a commit with
>>> whatever committer/author names you want and then push them in.
>>
>> Which is why you simply record the username of whoever pushed them in.
>>  This is what gitorious.org does etc.
>
> Not bad, but it's still very hard to trace properly.  Imagine I pull
> from a peer, then push my combined branch into the central repo.
> It'll say I'm pushing in patches from me *and* my friend.  Did I forge
> them or are they real?

While true, it's still traceable back to you. You did the push, so you are responsible for that code. It wouldn't be any different to just pushing a bad commit yourself.

Previous: Avery PennarunNext: walt
Message 5 of 13 in “Question about scm security holes”
  1. waltMar 4, 2010
  2. Avery PennarunMar 5, 2010
  3. John TapsellMar 5, 2010
  4. Avery PennarunMar 5, 2010
  5. John TapsellMar 5, 2010
  6. waltMar 5, 2010
  7. Avery PennarunMar 5, 2010
  8. Andreas KreyMar 5, 2010
  9. Johannes SchindelinMar 5, 2010
  10. Jakub NarebskiMar 5, 2010
  11. Avery PennarunMar 5, 2010
  12. Johannes SchindelinMar 5, 2010
  13. Daniel BarkalowMar 5, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.