CountVonGuetzli

↗ HN profile [ 59.6 ms ] full profile
Karma
0
Created
()
Submissions
0
  1. GitHub and GitLab will verify that a commit is signed by some key on the user's account. They won't let you require that it be signed by a specific key, like a hardware-backed YubiKey your org issued. So if an attacker…