git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC/PATCH v1] Add Travis CI support

From
Junio C Hamano <gitster@pobox.com>
Date
Sep 25, 2015, 00:41 UTC
Message-ID
<xmqqeghnuy8t.fsf@gitster.mtv.corp.google.com>
In-Reply-To
<1443131004-39284-1-git-send-email-larsxschneider@gmail.com>
larsxschneider@gmail.com writes:
> In order to avoid that in the future I configured Travis CI for Git. With this
> patch Travis can run all Git tests including the "git-p4" and "Git-LFS" tests.
Interesting.  I was wondering about the "p4" part myself.
> My idea is that the owner of "https://github.com/git/git" enables this account
> for Travis (it's free!). Then we would automatically get the test state for all
> official branches.

The last time I heard about this "it's free" thing, I thought I heard that it wants write access to the repository. If that is still the case, the history stored in the GitHub repository the "it's free" thing has access to can become even less trustworthy than it currently is. Those who clone/fetch from it cannot be sure if the tips of branches are what I pushed there, or they were changed to a malicious replacement from sideways by the "it's free" thing, taking advantage of that write access.

Granted, those who clone/fetch cannot be sure unless they trust GitHub. The only assurance they have is GitHub's word: "gitster has account with us, gitster pushes into this repository, and we have ACL to ensure that gitster is the only person that can update this repository". Allowing write-access to a third-party will break that assurance, even if you trust GitHub.

Of course, this can be improved if we start using signed push into GitHub. It is a separate issue in the sense that it would help GitHub to make that assurance stronger---those who fetch/clone can be assured that the tips of branches are what I pushed, without even trusting GitHub.

Previous: larsxschneider@gmail.comNext: Dennis Kaarsemaker
Message 3 of 31 in “Add Travis CI support”
  1. Add Travis CI supportlarsxschneider@gmail.com, Sep 24, 2015
  2. Add Travis CI supportlarsxschneider@gmail.com, Sep 24, 2015
  3. Junio C HamanoSep 25, 2015
  4. Dennis KaarsemakerSep 25, 2015
  5. Johannes SchindelinSep 25, 2015
  6. Luke DiamandSep 25, 2015
  7. Junio C HamanoSep 25, 2015
  8. Lars SchneiderSep 26, 2015
  9. Matthieu MoySep 27, 2015
  10. Stefan BellerSep 28, 2015
  11. Matthieu MoySep 28, 2015
  12. Junio C HamanoSep 28, 2015
  13. Matthieu MoySep 28, 2015
  14. Roberto TyleyOct 3, 2015
  15. Junio C HamanoOct 4, 2015
  16. Junio C HamanoOct 4, 2015
  17. Dennis KaarsemakerOct 4, 2015
  18. Johannes SchindelinOct 4, 2015
  19. Matthieu MoyOct 4, 2015
  20. Junio C HamanoOct 4, 2015
  21. Dennis KaarsemakerOct 4, 2015
  22. Matthieu MoyOct 5, 2015
  23. Junio C HamanoOct 5, 2015
  24. Sebastian SchuberthOct 12, 2015
  25. Junio C HamanoOct 4, 2015
  26. Jeff KingOct 4, 2015
  27. Sebastian SchuberthOct 2, 2015
  28. Jeff KingSep 25, 2015
  29. Junio C HamanoSep 25, 2015
  30. Jeff KingSep 25, 2015
  31. Shawn PearceSep 26, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.