home.social

#commitsigning — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #commitsigning, aggregated by home.social.

  1. One of the many reasons you should sign your git commits:

    github.com/OpenSourceMalware/P

    in short: infects your code via a malicious VS Code extension or NPM package, which in the end overwrites your last commit. You might never notice. But what it cannot do: sign that commit (as it does not have your key phrase). So a sudden unsigned commit gives you a chance to spot that "something weird happened".

    izzyondroid.org/docs/devpracti

    #security #git #commitSigning #signing

  2. One of the many reasons you should sign your git commits:

    github.com/OpenSourceMalware/P

    in short: infects your code via a malicious VS Code extension or NPM package, which in the end overwrites your last commit. You might never notice. But what it cannot do: sign that commit (as it does not have your key phrase). So a sudden unsigned commit gives you a chance to spot that "something weird happened".

    izzyondroid.org/docs/devpracti

    #security #git #commitSigning #signing

  3. One of the many reasons you should sign your git commits:

    github.com/OpenSourceMalware/P

    in short: infects your code via a malicious VS Code extension or NPM package, which in the end overwrites your last commit. You might never notice. But what it cannot do: sign that commit (as it does not have your key phrase). So a sudden unsigned commit gives you a chance to spot that "something weird happened".

    izzyondroid.org/docs/devpracti

    #security #git #commitSigning #signing

  4. One of the many reasons you should sign your git commits:

    github.com/OpenSourceMalware/P

    in short: infects your code via a malicious VS Code extension or NPM package, which in the end overwrites your last commit. You might never notice. But what it cannot do: sign that commit (as it does not have your key phrase). So a sudden unsigned commit gives you a chance to spot that "something weird happened".

    izzyondroid.org/docs/devpracti

    #security #git #commitSigning #signing

  5. Ah yes, in 2023, we're finally realizing that commit signing is "kinda wack" 🤡. Harley Watson bravely ventures into the complex world of version control—only to find himself baffled by his own #frustration with #GnuPG. Meanwhile, the rest of us are just trying to figure out why he bothered in the first place 🧐.
    lobi.to/writes/wacksigning/ #commitSigning #versionControl #techHumor #HackerNews #HackerNews #ngated

  6. Ah yes, in 2023, we're finally realizing that commit signing is "kinda wack" 🤡. Harley Watson bravely ventures into the complex world of version control—only to find himself baffled by his own #frustration with #GnuPG. Meanwhile, the rest of us are just trying to figure out why he bothered in the first place 🧐.
    lobi.to/writes/wacksigning/ #commitSigning #versionControl #techHumor #HackerNews #HackerNews #ngated