Rethinking Trust in Forge-Based Git Security
Aditya Sirish A Yelgundhalli, Patrick Zielinski, Reza Curtmola, Justin Cappos
Abstract
—Git is the most popular version control system today, with Git forges such as GitHub, GitLab, and Bitbucket used to add functionality. Significantly, these forges are used to enforce security controls. However, due to the lack of an open protocol for ensuring a repository’s integrity, forges cannot prove themselves to be trustworthy, and have to carry the responsibility of being non-verifiable trusted third parties in modern software supply chains. In this paper, we present gittuf, a system that decentralizes Git security and enables every user to contribute to collectively enforcing the repository’s security. First, gittuf enables distributing of policy declaration and management responsibilities among more parties such that no single user is trusted entirely or unilaterally. Second, gittuf decentralizes the tracking of repository activity, ensuring that a single entity cannot manipulate repository events. Third, gittuf decentralizes policy enforcement by enabling all developers to independently verify the policy, eliminating the single point of trust placed in the forge as the only arbiter for whether a change in the repository is authorized. Thus, gittuf can provide strong security guarantees in the event of a compromise of the centralized forge, the underlying infrastructure, or a subset of privileged developers trusted to set policy. gittuf also implements policy features that can protect against unauthorized changes to branches and tags ( i.e. , pushes) as well as files/folders ( i.e. , commits). Our analysis of gittuf shows that its properties and policy features provide protections against previously seen version control system attacks. In addition, our evaluation of gittuf shows it is viable even for large repositories with a high volume of activity such as those of Git and Kubernetes (less than 4% storage overhead and under 0.59s of time to verify each push). Currently, gittuf
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 62371206-93e6-490e-ac2c-d96f321cf056Cited by top-tier papers2
- Enhancing Legal Document Security and Accessibility with TAFRenata Vaderna, Dusan Nikolic, Patrick Zielinski, David Greisen et al.NDSS 2026 · 1 citation
- Trustworthy and Confidential SBOM ExchangeEman Abu Ishgair, Chinenye Okafor, Marcela S. Melara, Santiago Torres-AriasUSENIX Security 2026 · 1 citation
Builds on7
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola et al.USENIX Security 2019 · 98 citations
- A Systematic Analysis of the Juniper Dual EC IncidentStephen Checkoway, Jacob Maskiewicz, Christina Garman, Joshua Fried et al.CCS 2016 · 91 citations
- Sigstore: Software Signing for EverybodyZachary Newman, John Speed Meyers, Santiago Torres-AriasCCS 2022 · 35 citations
- On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software VulnerabilitiesSantiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin CapposUSENIX Security 2016 · 33 citations
- Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing FactorsTaylor R. Schorlemmer, Kelechi G. Kalu, Luke Chigges, Kyung Myung Ko et al.S&P 2024 · 17 citations
Related papers
- WAVE: A Decentralized Authorization Framework with Transitive DelegationMichael P. Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro et al.USENIX Security 2019 · 66 citations
- A Multi-Month Study of Git Commit SigningAbubakar Sadiq Shittu, John Sadik, Scott RuotiCCS 2026
- Unveiling Security Vulnerabilities in Git Large File Storage ProtocolYuan Chen, Qinying Wang, Yong Yang, Yuanchao Chen et al.S&P 2025
- Ghostor: Toward a Secure Data-Sharing System from Decentralized TrustYuncong Hu, Sam Kumar, Raluca Ada PopaNSDI 2020 · 48 citations
- End-to-End Encrypted Git ServicesYa-Nan Li, Yaqing Song, Qiang Tang, Moti YungCCS 2025 · 1 citation
