Re: commit signing

2022-09-14 Thread Ulrich Drepper via Gcc
On Wed, Sep 14, 2022 at 1:31 PM Richard Biener wrote: > How does this improve supply chain security if the signing happens > automagically rather than manually at points somebody actually > did extra verification? It works only automatically if you have ssh-agent (and/or gpg-agent) running. I

Re: commit signing

2022-09-14 Thread Jakub Jelinek via Gcc
On Wed, Sep 14, 2022 at 01:31:06PM +0200, Richard Biener via Gcc wrote: > How does this improve supply chain security if the signing happens > automagically rather than manually at points somebody actually > did extra verification? That is, what's the attack vector this helps with? > > What's the

Re: commit signing

2022-09-14 Thread Richard Biener via Gcc
On Wed, Sep 14, 2022 at 11:12 AM Ulrich Drepper via Gcc wrote: > > For my own projects I started /automatically/ signing all the git commits. > This is so far not that important for my private projects but it is > actually important for projects like gcc. It adds another layer of > security to th

[EXT] EFT Remittance to gcc has been deposited on Wednesday, September 14, 2022

2022-09-14 Thread Account#622 via Gcc
Dear gcc, Please see attached paid invoice. Thank you for your business! InnovativePay Due date:15/09/2022 7:09 PM For: gcc@gcc.gnu.org gcc.gnu.org

Re: commit signing

2022-09-14 Thread Jonathan Wakely via Gcc
On Wed, 14 Sept 2022 at 10:12, Ulrich Drepper wrote: > The key creation ideally is a one-time effort. The git configuration is > for everyone using the gcc git tree a once-per-local-repository effort (and > can be scripted, the gcc repo could even contain a script for that). No opinion yet on the

commit signing

2022-09-14 Thread Ulrich Drepper via Gcc
For my own projects I started /automatically/ signing all the git commits. This is so far not that important for my private projects but it is actually important for projects like gcc. It adds another layer of security to the supply chain security. My shell prompt (as many other people's as well)