From kde-scm-interest Sat Nov 14 21:23:22 2009 From: Chani Date: Sat, 14 Nov 2009 21:23:22 +0000 To: kde-scm-interest Subject: Re: [Kde-scm-interest] accountability Message-Id: <200911141323.23649.chanika () gmail ! com> X-MARC-Message: https://marc.info/?l=kde-scm-interest&m=125823381326459 MIME-Version: 1 Content-Type: multipart/mixed; boundary="--===============1772282825==" --===============1772282825== Content-Type: multipart/signed; boundary="nextPart2195089.ly264o2LMC"; protocol="application/pgp-signature"; micalg=pgp-sha1 Content-Transfer-Encoding: 7bit --nextPart2195089.ly264o2LMC Content-Type: Text/Plain; charset="iso-8859-15" Content-Transfer-Encoding: quoted-printable On November 13, 2009 08:06:49 Jeff Mitchell wrote: > Ian Monroe wrote: > > Which is why I like my simple flat-file log idea (a log of commit > > hash, user id, maybe time). It doesn't open up any privacy issues > > (since the info is already public) and would solve the problem by > > using the commit hash, which is a nice security feature of git. >=20 > You still have an issue in that the user id is internal to Gitorious and > is meaningless without also providing further information, like email > address, name, public ssh key, or some such thing. >=20 > All of those could be seen as potential privacy issues; for instance, > you might think the email address would be obvious, but what if a person > is committing under a different email address than what they've given to > Gitorious? >=20 > --Jeff >=20 I still don't understand why we need access to email addresses from some=20 gitorious database anyways. if you want to push to a kde repo, you have to = be=20 in the kde-developers group. we can require people to agree to whatever's=20 needed at the time they join that group. all we need is a log of which kde= =20 developer pushed what, right? everything else you can get from a git clone... =2D-=20 This message brought to you by eevil bananas and the number 3. www.chani3.com --nextPart2195089.ly264o2LMC Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEABECAAYFAkr/H8sACgkQeGbAwpIS3GzsEgCfV628tMVGSW5M//n/tOjlgBfN dIgAn3HcTxTfKubWj60LtU1QuoYemdDX =f+7X -----END PGP SIGNATURE----- --nextPart2195089.ly264o2LMC-- --===============1772282825== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Kde-scm-interest mailing list Kde-scm-interest@kde.org https://mail.kde.org/mailman/listinfo/kde-scm-interest --===============1772282825==--