3 ms·
Anyone successfully get a workplace to have signed commits? I've struggled to describe the wins. The risks are risks a lot of companies have to take on anyways
by codemac 11y ago
Anyone successfully get a workplace to have signed commits?
I've struggled to describe the wins. The risks are risks a lot of companies have to take on anyways due to other parts of their infrastructure, and generally end up ameliorating with signed blobs/releases.
- hackcasual 11y agoThis probably isn't worth managing the PKI for a workplace, but this should be good for open source contributions
- michaelt 11y agoAt my workplace we tried signed hg commits for a little over a year. Perhaps it was the relative inexperience of our team, coming from our subversion background, or it might be that we didn't adopt the best tools out there, but it was a lot of work for largely hypothetical benefits. We had a system involving a third-party extension to hg, and an agent that was supposed to work on Windows, Mac and OS X - but it never seemed 100% reliable on any of those platforms. We were also inexperienced enough that if, say, someone committed something while their signing was set up wrong we weren't able to figure out how to retroactively sign the commits. We also used x509 certificates issued by a central corporate IT team that issued them manually, and expired the certificates annually without automatically issuing replacements. I'm sure some of these issues were with our team/organisation rather than the tools themselves, but when the opportunity arose to switch to gitlab with no commit signing required whatsoever, we switched immediately.