Gentoo Archives: gentoo-dev

From: Kent Fredric <kentfredric@×××××.com>
To: gentoo-dev <gentoo-dev@l.g.o>
Subject: Re: [gentoo-dev] Re: git security (SHA-1)
Date: Sat, 20 Sep 2014 21:24:58
Message-Id: CAATnKFCO+SyHuEU2GN4qirD35rVx62JEyXp=NO3Zmus3QQpQBg@mail.gmail.com
In Reply to: Re: [gentoo-dev] Re: git security (SHA-1) by hasufell
1 On 21 September 2014 09:18, hasufell <hasufell@g.o> wrote:
2
3 > I didn't see him saying that. It rather sounds like we want to have
4 > thick signed Manifests and break pull requests and whatnot.
5 >
6
7 Those aren't the only options.
8
9 We could of course develop a custom commit signature system, either in the
10 commit itself, or using a custom ref protocol.
11
12 For instance, you could have an object in refs/signatures/<*> for every
13 blob in the tree, signed by the person who created that blob. But you'd
14 probably have to hook the git client somewhere low-level to make that
15 option work, and that way, those refs could be pulled only by people who
16 wanted them (Speed!), *and* they could be created after-the-fact.
17
18
19 --
20 Kent
21
22 *KENTNL* - https://metacpan.org/author/KENTNL