git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Tracability in git commits
@ 2008-04-29 12:55 Richard Purdie
  2008-04-29 16:08 ` Johannes Schindelin
                   ` (2 more replies)
  0 siblings, 3 replies; 15+ messages in thread
From: Richard Purdie @ 2008-04-29 12:55 UTC (permalink / raw)
  To: git

Hi,

I've been wondering about whether its possible to provide some degree of
traceability of commits to a shared git repository. The potential
nightmare scenario is one developer making a commit pretending to be
someone else.

Assuming a shared server using something like gitosis each set of
commits is made under a certain ssh ID and what I'd like is to be able
to validate that against the commits so we could tell that commits A-D
were made by ID Z.

I see a repository as a linear progression of commits and merges.

The simplest security check would check each commit/merge on this linear
progression and make sure it matches the ssh ID. The problem is where
someone merges in some external tree, someone else pulls it and pushes
it, only fast forward merges are made and the ssh 'ID' no longer matches
the ID of the merge which is in the linear path.

Someone mentioned some patches that are on the mailing list atm and the
idea of never allowing fast forward merges. Would the "never" policy of
fast forward merges solve this problem? Is there a simpler way to
address this or are there problems I'm not seeing?

Regards,

Richard

^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2008-05-01 22:22 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-04-29 12:55 Tracability in git commits Richard Purdie
2008-04-29 16:08 ` Johannes Schindelin
2008-04-29 21:34 ` Junio C Hamano
2008-04-29 21:56   ` Richard Purdie
2008-04-30  2:51     ` Shawn O. Pearce
2008-04-30 17:33   ` Ping Yin
2008-04-30 19:46     ` Miklos Vajna
2008-05-01  0:28       ` Shawn O. Pearce
2008-05-01  5:09         ` Ping Yin
2008-04-30 10:06 ` Jakub Narebski
2008-04-30 10:32   ` Richard Purdie
2008-05-01  1:26     ` Martin Langhoff
2008-05-01  7:34       ` Martin Langhoff
2008-05-01 19:03         ` Junio C Hamano
2008-05-01 22:21           ` Martin Langhoff

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).