Hacker News new | past | comments | ask | show | jobs | submit login

There are stakeholders who want Real Name digital signatures for git commits to "critical" open-source software and every dependency. There is already a numerical score for OSS which determines whether bug fixes will be funded by Google and others,

https://openssf.org/press-release/2021/10/13/open-source-sec...




That sounds like a way to punish malicious committers rather than prevent malicious commits.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: