Enforce opt-in signed Git Commits and Tags
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
調査の方向性
Issue にはファイル、テスト、エントリーポイントが記載されていません。まず、追跡されている3つの目標を確認してください。共有 GitHub Actions ワークフローを作成すること、LoopBack リポジトリ全体で使用すること、maintainer の PGP 公開鍵を公開することです。3つのチェックリスト項目すべてに対応したら完了です。
索引モデルが issue の本文から書いたものです。
説明
Currently, we do not enforce PGP-signed Git Commits or Tags. This means that those who expect their contributions to be PGP-signed cannot enforce this policy across the loopbackio Git Repositories. Instead, each Pull Request would need to be manually reviewed for the respective Git Commits and Git Signatures.
This poses a potential security risk as:
- It is error-prone (e.g. Maintainers forget to check for verified Git Commits and Git Tags)
- The lifecycle of the PGP Keys is not clearly tracked
To add or remove verified PGP Keys from a GitHub account does not require any publicly-visible evaluation or acknowledgement from other LoopBack Maintianers.
GitHub does provide a mechanism to enforce signed Git Commits and Tags. However:
- This does not work for the
rebase and mergeworkflow, which we leverage (i.e. the GitHub check mechanism does not pass).
Exact reasons are unclear since the resulting Git Commits and Git Tags still have a valid PGP Signature. - It can only be enforced for everyone or no one
The LoopBack Project is a general open-source project, hence enforcing signed commits for every contributor would significantly raise the contribution barrier. Furthermore, this does not solve the problem of managing the PGP Keys' lifecycle in an open and transparent manner.
To combat this issue, LoopBack Maintainers who want to enforce valid, PGP-signed Git Commits and Git Tags should publish their PGP Public Key in this Git Repository, which will then be leveraged by a shared GitHub Action Workflow across the loopbackio Git Repositories to enforce this policy.
This issue is to track:
- The creation of the shared GitHub Action Workflow
- Usage of the shared GitHub Action Workflow across
loopbackioGit Repositories - The publishing of LoopBack Maintainers' PGP Public Keys
- 主要言語
- TypeScript
- スター
- 4
- フォーク
- 1
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
loopbackio/security のほかの issue
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
loopbackio/security#42 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
loopbackio/security#41 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
loopbackio/security#40 ·
-
openjsf
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
loopbackio/security#39 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
loopbackio/security#38 ·
loopbackio/security の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
bug:new
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
callstackincubator/simlock#350 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
openwatersio/maritime-zones#33 ·
メンテナーはふだん 1 日以内に返信
-
Booking email verification fails for plus aliases with impersonation protection enabled対応中かも @kankadev が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
calcom/cal.diy#30293 · コメント 1 件 ·
メンテナーはふだん 5 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
AOSSIE-Org/DebateAI#611 ·
メンテナーはふだん 3 日以内に返信