2 ms·
This has been around for quite a while now; I made a post on my blog about it back in 2013: http://www.jayhuang.org/blog/pushing-code-to-github-as-linus-torvald
by jayhuang 11y ago
This has been around for quite a while now; I made a post on my blog about it back in 2013: http://www.jayhuang.org/blog/pushing-code-to-github-as-linus-torvalds/ http://www.jayhuang.org/blog/pushing-code-to-github-as-linus...
Of course this doesn't actually give you access to the person's account, but UX wise, it's incredibly misleading for someone to click a commit in my repository by "torvalds" and have it actually go to his profile. My issue is very much with the social implications of this as opposed to it being an actual security issue (see: signed commits).
There should be some indication at the very least that a commit is not signed.