3 ms·
I'm not sure it is. Software development has become more decentralized and more complex than it was 20 years ago. It's also much more accessible to more people
by _wldu 4y ago
I'm not sure it is. Software development has become more decentralized and more complex than it was 20 years ago. It's also much more accessible to more people who may be great programmers but not really aware of code/repository security.
Most software developers do not sign their git commits. And if they do, they probably aren't doing it properly (store keys on a YubiKey or only use QubesOS with an isolated dev qube and split GPG).
If you do any sort of dev work, you really need to isolate that activity from the other things you do online and generate a signing only GPG subkey and handle it properly and sign all of your git commits. I think this is vital to ensuring code integrity as if you do not do this, you probably won't even realize when someone has tampered with your code.
Hope this helps.