5 ms·
Everyone should PGP sign their git commits with a secret key stored on a YubiKey. Make small changes to your code, read the diff, then commit and sign before pu
by _wldu 4y ago
Everyone should PGP sign their git commits with a secret key stored on a YubiKey. Make small changes to your code, read the diff, then commit and sign before pushing to the repo. IMPO, that's really the only way to protect the integrity of source code.
If you are adding large changes without carefully reading the diffs and you do not sign the commits it's just a matter of time.
- jsiepkes 4y agoWould be nice if you could also use a timestamping service when signing your commit. That way even if your key is compromised you can still spot things that were signed after the compromise.
- andrewstuart2 4y agoYou don't even need that for historical integrity checks either. As long as the commit history exists in two places, it's trivial to detect when one has changed, due to the merkle tree structure of the commit log. Signed commits are a nice way of also sealing that history and validating authorship or approval of some sort.