git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[ANNOUNCE] git-sign, simple scripts to generate and verify securely signed Git checkouts

From
CJChristian Jaeger <chrjae@gmail.com>
Date
Mar 13, 2017, 14:22 UTC
Message-ID
<CAEjYwfWP50JGd7HmP4hVq=Fob3nV0xqc9AuJ0wHreq4HTeSsWw@mail.gmail.com>
Hi

Mostly as a proof of concept, I've created two scripts to sign and verify Git checkouts (I'm saying checkouts since it (both for simplicity, and probably trust) is based on the working directory contents, not the tree referred to by the signed commit). Like some other such solutions, this adds secure hashes to the signed tag message. There are two drawbacks and one advantage versus other solutions:

- meant for small repositories only (each file in the repository takes
up a line in the tag message)
- relatively hacky, e.g. newlines in file names may be problematic,
doesn't currently use gpg's --status-fd or --with-colons, and doesn't
check git config
+ easily verifiable scripts, checking can even be done manually (hence
no need for casual users to (blindly) trust third party code)
https://github.com/pflanze/git-sign
Christian.
Message 1 of 1 in “[ANNOUNCE] git-sign, simple scripts to generate and verify securely signed Git checkouts”
  1. Christian JaegerMar 13, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.