4 ms·
What’s the reason I would want to do this? Is there a specific threat I need to be aware of with regard to threat vector on git commits?
by sethherr 3y ago
What’s the reason I would want to do this? Is there a specific threat I need to be aware of with regard to threat vector on git commits?
- cdchn 3y agoSBOM/chain of custody all the way back to an individual doing a commit.
- sethherr 3y agoThis is the opposite of a specific threat vector
- cdchn 3y agoSoftware supply chain attacks not specific enough?
- lima 3y agoNot in terms of specific threat model.
- computerfriend 3y agoThreat: attacker can commit malicious code to a repository by impersonation. Mitigation: verify commit signatures.
- atoav 3y agoWe are on computers, so everything can be changed all the time. E.g. there could be malware that changes a cloned git repos commits before you compile the software. If the commits are signed that malware would have to know the private key of that dev to do that, which is one additional hurdle that makes this kind of attack way harder to pull off.
- nprateem 3y agoIdeally your CD system would refuse to deploy commits signed with keys it doesn't recognise, but I've never seen that implemented.
- hannob 3y agoIn Gentoo, I believe we already reject pushing unsigned commits.
- deleted 3y ago[deleted]
- okamiueru 3y agoWhat is "this"? - If "sign with SSH instead of GPG", the answer is convenience. - If "sign commits", the answer is authentication of the user of the commit. Encryption part isn't relevant as you get that already regardless with https/ssh protocols when communicating with the git server. As for why you want to authenticate the user, the better question to ask, is, why wouldn't you? No one can push any commit on your behalf. In some cases it is extremely important because certain branches might be protected due to automated CI/CD pipelines that contain secrets. Without enforcing verification of authenticity, a user might push a commit pretending to be a different user, which exposes those secrets. One might say "well, then you have a bigger problem in your organization", which leads to the restated question of "why not?". It just one of those things we do, like health care workers washing their hands.