git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Commit signing

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Jan 15, 2007, 10:43 UTC
Message-ID
<Pine.LNX.4.63.0701151137430.22628@wbgn013.biozentrum.uni-wuerzburg.de>
In-Reply-To
<20070115102727.GC12257@spearce.org>
Hi,
On Mon, 15 Jan 2007, Shawn O. Pearce wrote:
> I've never met anyone on this mailing list in person, but the quality 
> (or lack thereof sometimes) is evident in my work, and since its all 
> peer-reviewed anyway Junio finds little risk in incorporating the good 
> stuff into git.git.  No certificate required.

Exactly. I think it is one of the reasons monotone is so unpopular (at least as far as I am concerned): it makes the start really cumbersome. And in the end you gain nothing.

And you see what the result is when looking into corporate projects. More often than not, bureaucratic procedures (e.g. tracking time, meetings, specifications) supersede quality-assuring procedures (e.g. permanent updates on the TODO list, code review, discussion on implementation details), and quite often, the code just sucks.

My favourite example is when I found 34 different (!) implementations of a tree structure in the same project.

So, if you start relying on the validity of code just because somebody signed it, you will reap trouble.

Ciao, Dscho

Previous: Shawn O. PearceNext: Daniel Barkalow
Message 5 of 21 in “Commit signing”
  1. Andy ParkinsJan 15, 2007
  2. Matthias KestenholzJan 15, 2007
  3. Shawn O. PearceJan 15, 2007
  4. Shawn O. PearceJan 15, 2007
  5. Johannes SchindelinJan 15, 2007
  6. Daniel BarkalowJan 15, 2007
  7. Johannes SchindelinJan 15, 2007
  8. Shawn O. PearceJan 15, 2007
  9. Karl HasselströmJan 15, 2007
  10. Andy ParkinsJan 15, 2007
  11. Shawn O. PearceJan 15, 2007
  12. Johannes SchindelinJan 15, 2007
  13. Andy ParkinsJan 15, 2007
  14. Johannes SchindelinJan 15, 2007
  15. Andy ParkinsJan 15, 2007
  16. Martin LanghoffJan 15, 2007
  17. Andy ParkinsJan 15, 2007
  18. Martin LanghoffJan 15, 2007
  19. Johannes SchindelinJan 15, 2007
  20. Jakub NarebskiJan 15, 2007
  21. Jeff KingJan 15, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.