Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why do you say that? It seems like they would be more important in the context of supply chain attacks.


If they were able to get your keys to push a commit or sneak code into your branch we are waaaaay past the territory where a signed commit can be trusted.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: