1 |
Hi, |
2 |
|
3 |
On 09/15/2014 01:37 AM, Kent Fredric wrote: |
4 |
> On 15 September 2014 11:25, hasufell <hasufell@g.o> wrote: |
5 |
> |
6 |
>> Robin said |
7 |
>>> The Git commit-signing design explicitly signs the entire commit, |
8 |
>> including blob contents, to avoid this security problem. |
9 |
>> |
10 |
>> Is this correct or not? |
11 |
>> |
12 |
> |
13 |
> I can verify a commit by hand with only the commit object and gpg, but |
14 |
> without any of the trees or parents. |
15 |
> |
16 |
> https://gist.github.com/kentfredric/8448fe55ffab7d314ecb |
17 |
> |
18 |
> |
19 |
|
20 |
So signing of git commits does not guarantee enough security (taking |
21 |
that SHA1 is weak and can be broken), right? Could we than just use |
22 |
usual (not thin) manifests? |
23 |
|
24 |
-- |
25 |
Jauhien |