[libre-riscv-dev] [Bug 322] New: deploy git commit signoff and git tag signing

bugzilla-daemon at libre-soc.org bugzilla-daemon at libre-soc.org
Mon May 18 22:01:58 BST 2020


https://bugs.libre-soc.org/show_bug.cgi?id=322

            Bug ID: 322
           Summary: deploy git commit signoff and git tag signing
           Product: Libre-SOC's first SoC
           Version: unspecified
          Hardware: Other
                OS: Linux
            Status: CONFIRMED
          Severity: enhancement
          Priority: ---
         Component: Source Code
          Assignee: lkcl at lkcl.net
          Reporter: lkcl at lkcl.net
                CC: libre-riscv-dev at lists.libre-riscv.org
   NLnet milestone: ---

https://bugs.libre-soc.org/show_bug.cgi?id=266#c3

relying solely on https paints a hacking target on our server.  if however the
commits or tags are GPG signed, these are offline, distributed, and harder to
compromise.

this will become relevant when we start doing releases.

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the libre-riscv-dev mailing list