Re: Tags
- From
Eric W. Biederman <ebiederm@xmission.com>
- Date
- Jul 2, 2005, 17:54 UTC
- Message-ID
- <m1k6k9drfk.fsf@ebiederm.dsl.xmission.com>
- In-Reply-To
- <42C6D318.8050108@zytor.com>
"H. Peter Anvin" <hpa@zytor.com> writes:
Show 8 quoted lines
> Eric W. Biederman wrote: >> However all you have to do for your single system git repository is >> to filter tags at creation time. So for a person to upload something >> you need a git aware tool and you need authentication so you are certain >> it is the right person creating the tag. > > That's complicated; it pretty much works out to having to have a PKI and a > system of registered IDs, or some such. That's painful.
?? Isn't that what ssh is?
To some extent a lot depends on how active you expect people to try and forge things. If there is an expectation of honesty you are fine.
If you want to build one mondo repository with thousands of developers having write access you need to be more careful. But as far as I know none of that is specific to tags.
Eric