Follow

@mikaela
I think that Githubs logic is correct because hypotheticaly attacker who got your signing keys could also commit, and Github does not know for how long has been attacker doing those commits (maybe dev has been on vacation, lost access to his/her keys etc) so Github has no choice but to revoke all commits for sake of end user.

Sign in to participate in the conversation
Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!