git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Question about scm security holes

From
Wwalt <w41ter@gmail.com>
Date
Mar 5, 2010, 03:20 UTC
Message-ID
<4B907884.5080501@gmail.com>
In-Reply-To
<32541b131003041803q9abf6baq4cf9ffcca990b51c@mail.gmail.com>
On 03/04/2010 06:03 PM, Avery Pennarun wrote:
> ...you can create a commit with
> whatever committer/author names you want and then push them in.
> Commits aren't GPG-signed, only tags are, so there are lots of ways to
> forge a commit from someone else and mess up the audit log...

Thanks, that's the kind of reply I was hoping for. Do you think there should be a way to sign the commits themselves, at least as an option?

I certainly wouldn't bother, but OTOH nobody wants to steal my code :-/

Do you suppose the devs at Adobe carry the complete source repository home on their laptops every night? (Not if they use Perforce, of course, but they might if they adopted git as their scm.)

Previous: John TapsellNext: Avery Pennarun
Message 6 of 13 in “Question about scm security holes”
  1. waltMar 4, 2010
  2. Avery PennarunMar 5, 2010
  3. John TapsellMar 5, 2010
  4. Avery PennarunMar 5, 2010
  5. John TapsellMar 5, 2010
  6. waltMar 5, 2010
  7. Avery PennarunMar 5, 2010
  8. Andreas KreyMar 5, 2010
  9. Johannes SchindelinMar 5, 2010
  10. Jakub NarebskiMar 5, 2010
  11. Avery PennarunMar 5, 2010
  12. Johannes SchindelinMar 5, 2010
  13. Daniel BarkalowMar 5, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.