Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
wlynch
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
What the Fork: Imposter Commits in GitHub Actions and CI/CD
(chainguard.dev)
11 points
by
wlynch
4y ago
|
0 comments
2.
▲
by
wlynch
4y ago
You may want to check out https://github.com/sigstore/gitsign ! You can generate ephemeral x509 code signing certs for free using Sigstore. (disclosure: I'm a maintainer for gitsign)
3.
▲
by
wlynch
4y ago
+1 to this! https://docs.sigstore.dev/fulcio/certificate-issuing-overvie... has a good overview of how the certificate issuing works. With Gitsign, by default a new keypair is generated per signing event (i.e. per comm
4.
▲
by
wlynch
4y ago
Worth calling out that gitsign works with any Git host for the commit signatures / verification! The main piece that's platform specific is the Verified badges that you see in the UI + any CI checks.
5.
▲
by
wlynch
4y ago
You can find the feature request for supporting keyless sigstore/gitsign at https://gitlab.com/gitlab-org/gitlab/-/issues/364428
6.
▲
by
wlynch
4y ago
Balancing privacy vs transparency is definitely something that's tricky! You may be interested in https://blog.sigstore.dev/privacy-in-sigstore-57cac15af0d0 which goes into some of the background of why email addresses
7.
▲
Introducing Gitsign – Keyless Git commit signing with Sigstore
(blog.sigstore.dev)
14 points
by
wlynch
4y ago
|
0 comments
8.
▲
by
wlynch
8y ago
See https://cloud.google.com/cloud-build/docs/securing-builds/us...