Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Enforce opt-in signed Git Commits and Tags

オープン
#18 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
25/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
git, github-actions
領域
ci-cd, security

調査の方向性

Issue にはファイル、テスト、エントリーポイントが記載されていません。まず、追跡されている3つの目標を確認してください。共有 GitHub Actions ワークフローを作成すること、LoopBack リポジトリ全体で使用すること、maintainer の PGP 公開鍵を公開することです。3つのチェックリスト項目すべてに対応したら完了です。

索引モデルが issue の本文から書いたものです。

説明

Currently, we do not enforce PGP-signed Git Commits or Tags. This means that those who expect their contributions to be PGP-signed cannot enforce this policy across the loopbackio Git Repositories. Instead, each Pull Request would need to be manually reviewed for the respective Git Commits and Git Signatures.

This poses a potential security risk as:

  1. It is error-prone (e.g. Maintainers forget to check for verified Git Commits and Git Tags)
  2. The lifecycle of the PGP Keys is not clearly tracked
    To add or remove verified PGP Keys from a GitHub account does not require any publicly-visible evaluation or acknowledgement from other LoopBack Maintianers.

GitHub does provide a mechanism to enforce signed Git Commits and Tags. However:

  1. This does not work for the rebase and merge workflow, which we leverage (i.e. the GitHub check mechanism does not pass).
    Exact reasons are unclear since the resulting Git Commits and Git Tags still have a valid PGP Signature.
  2. It can only be enforced for everyone or no one
    The LoopBack Project is a general open-source project, hence enforcing signed commits for every contributor would significantly raise the contribution barrier. Furthermore, this does not solve the problem of managing the PGP Keys' lifecycle in an open and transparent manner.

To combat this issue, LoopBack Maintainers who want to enforce valid, PGP-signed Git Commits and Git Tags should publish their PGP Public Key in this Git Repository, which will then be leveraged by a shared GitHub Action Workflow across the loopbackio Git Repositories to enforce this policy.

This issue is to track:

  • The creation of the shared GitHub Action Workflow
  • Usage of the shared GitHub Action Workflow across loopbackio Git Repositories
  • The publishing of LoopBack Maintainers' PGP Public Keys
主要言語
TypeScript
スター
4
フォーク
1
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

loopbackio/security のほかの issue

loopbackio/security の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。