| ▲ | zygentoma 7 hours ago | |||||||||||||||||||
Sorry, no. When I check out code from a git repository in a pipeline using a git hash, I expect the code to be exactly what has been reviewed by me under that hash. Everything else would just be a crazy invitation to make supply chain attacks uncircumventable. | ||||||||||||||||||||
| ▲ | kazinator 6 hours ago | parent [-] | |||||||||||||||||||
And so if you don't trust the server that is hosted on or the security of the transport mechanism like TLS/SSL, such that the content may be manipulated by adversaries, you think that git hashes are good enough? Well, what about someone who is fetching the commit from that server for the first time and has nothing to compare the hash against? Oh, that would never be a problem for widely disseminated, popular, open source project, so it doesn't matter. | ||||||||||||||||||||
| ||||||||||||||||||||