3 ms·
Having openpgp-signed commits would prevent such an issue.
by dependenttypes 6y ago
Having openpgp-signed commits would prevent such an issue.
- jlgaddis 6y agoWould it? Couldn't the "hacker" have simply generated a new GPG key and added it to the account he had control of?
- dependenttypes 6y agoThe users would have specific keys trusted.