Re: Question about scm security holes
- From
- walt <w41ter@gmail.com>
- Date
- Mar 5, 2010, 03:20 UTC
- Message-ID
- <4B907884.5080501@gmail.com>
- In-Reply-To
- <32541b131003041803q9abf6baq4cf9ffcca990b51c@mail.gmail.com>
On 03/04/2010 06:03 PM, Avery Pennarun wrote:
> ...you can create a commit with > whatever committer/author names you want and then push them in. > Commits aren't GPG-signed, only tags are, so there are lots of ways to > forge a commit from someone else and mess up the audit log...
Thanks, that's the kind of reply I was hoping for. Do you think there should be a way to sign the commits themselves, at least as an option?
I certainly wouldn't bother, but OTOH nobody wants to steal my code :-/
Do you suppose the devs at Adobe carry the complete source repository home on their laptops every night? (Not if they use Perforce, of course, but they might if they adopted git as their scm.)