Code review in the Linux kernel still happens by email to a large degree.
Further up in contribution tree there is additional signing. Would that further complicate the insertion of a false commit? I am not convinced that signing is used all the way down to every contribution.
Comments
Code review in the Linux kernel still happens by email to a large degree.
Further up in contribution tree there is additional signing. Would that further complicate the insertion of a false commit? I am not convinced that signing is used all the way down to every contribution.
Linux probably has enough eyeballs on its source to make attacks like that unlikely anyway, but Git isn't just used by Linux.