Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For your first point, can't you verify the signature for the commit? In order to to compromise the origin, they must also compromise the secret key of whoever is signing commits.

I say that in full realization that 99% of people probably don't even know that you can sign commits, but the first point doesn't seem valid, as you can ensure integrity of commit history.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: