Gentoo Archives: gentoo-dev

From: Gordon Pettey <petteyg359@×××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: git security (SHA-1)
Date: Sun, 21 Sep 2014 03:08:40
Message-Id: CAHY5MefhGxQpU3ev+fQbzWsv4apJdJVH76-xWXGsVVLLtrcyXw@mail.gmail.com
In Reply to: Re: [gentoo-dev] Re: git security (SHA-1) by Peter Stuge
1 On Sat, Sep 20, 2014 at 8:20 PM, Rich Freeman <rich0@g.o> wrote:
2 On Sat, Sep 20, 2014 at 8:58 PM, Gordon Pettey <petteyg359@×××××.com> wrote:
3 > You're following the wrong train down the wrong tracks. Git [0-9a-f]{40}
4 is
5 > to CVS 1[.][1-9][0-9]+. You're arguing that CVS is more secure because its
6 > commits are sequential numbers.
7
8 Ulrich is well-aware of that. His argument is that with cvs there is
9 no security whatsoever in the scm, and so there is more interest in
10 layering security on-top. With git there is more of a tendency to
11 rely on the less-than-robust commit signing system.
12
13 On Sat, Sep 20, 2014 at 9:17 PM, Peter Stuge <peter@×××××.se> wrote:
14
15 > Rich Freeman wrote:
16 > > > I've so far gotten zero feedback on my hosting offer, intended to
17 > > > help find some starting processes.
18 > >
19 > > hassufel's repository on github should be more than adequate:
20 > > https://github.com/gentoo/gentoo-gitmig
21 >
22 > The very first email in this thread pointed out that it is difficult
23 > to do anything custom on github, so I offered to help because I'm
24 > willing and able to help arrange hooks and scripting and whatever foo
25 > may be needed to move on.
26 >
27
28 I can set up something in New York and/or Germany if additional hosts are
29 needed.