Author: Jeff Garzik 2013-04-03 03:51:45
Published on: 2013-04-03T03:51:45+00:00
In an email conversation between Wladimir and Jeff Garzik on April 2, 2013, a suggestion was made to start gpg signing commits for Bitcoin like the Linux kernel. However, it was pointed out that this would rule out using GitHub for merging without manual steps. Jeff Garzik acknowledged this but noted that he personally reads the code before approving it, which is more important than the author. He also expressed concern about the possibility of a race where someone uploads an innocent branch, creates a pull request, and then rebases the branch to something evil just before the merge. Jeff Garzik is affiliated with exMULTI, Inc.
Updated on: 2023-06-06T11:30:32.270629+00:00