Rethinking Trust in Forge-Based Git Security
Aditya Sirish A Yelgundhalli, Patrick Zielinski, Reza Curtmola, Justin Cappos
摘要
—Git is the most popular version control system today, with Git forges such as GitHub, GitLab, and Bitbucket used to add functionality. Significantly, these forges are used to enforce security controls. However, due to the lack of an open protocol for ensuring a repository’s integrity, forges cannot prove themselves to be trustworthy, and have to carry the responsibility of being non-verifiable trusted third parties in modern software supply chains. In this paper, we present gittuf, a system that decentralizes Git security and enables every user to contribute to collectively enforcing the repository’s security. First, gittuf enables distributing of policy declaration and management responsibilities among more parties such that no single user is trusted entirely or unilaterally. Second, gittuf decentralizes the tracking of repository activity, ensuring that a single entity cannot manipulate repository events. Third, gittuf decentralizes policy enforcement by enabling all developers to independently verify the policy, eliminating the single point of trust placed in the forge as the only arbiter for whether a change in the repository is authorized. Thus, gittuf can provide strong security guarantees in the event of a compromise of the centralized forge, the underlying infrastructure, or a subset of privileged developers trusted to set policy. gittuf also implements policy features that can protect against unauthorized changes to branches and tags ( i.e. , pushes) as well as files/folders ( i.e. , commits). Our analysis of gittuf shows that its properties and policy features provide protections against previously seen version control system attacks. In addition, our evaluation of gittuf shows it is viable even for large repositories with a high volume of activity such as those of Git and Kubernetes (less than 4% storage overhead and under 0.59s of time to verify each push). Currently, gittuf
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Enhancing Legal Document Security and Accessibility with TAFRenata Vaderna, Dusan Nikolic, Patrick Zielinski, David Greisen 等NDSS 2026 · 被引用 1 次
- Trustworthy and Confidential SBOM ExchangeEman Abu Ishgair, Chinenye Okafor, Marcela S. Melara, Santiago Torres-AriasUSENIX Security 2026 · 被引用 1 次
它引用的顶会 Paper7
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola 等USENIX Security 2019 · 被引用 98 次
- A Systematic Analysis of the Juniper Dual EC IncidentStephen Checkoway, Jacob Maskiewicz, Christina Garman, Joshua Fried 等CCS 2016 · 被引用 91 次
- Sigstore: Software Signing for EverybodyZachary Newman, John Speed Meyers, Santiago Torres-AriasCCS 2022 · 被引用 35 次
- On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software VulnerabilitiesSantiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin CapposUSENIX Security 2016 · 被引用 33 次
- Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing FactorsTaylor R. Schorlemmer, Kelechi G. Kalu, Luke Chigges, Kyung Myung Ko 等S&P 2024 · 被引用 17 次
相关 Paper
- WAVE: A Decentralized Authorization Framework with Transitive DelegationMichael P. Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro 等USENIX Security 2019 · 被引用 66 次
- A Multi-Month Study of Git Commit SigningAbubakar Sadiq Shittu, John Sadik, Scott RuotiCCS 2026
- Unveiling Security Vulnerabilities in Git Large File Storage ProtocolYuan Chen, Qinying Wang, Yong Yang, Yuanchao Chen 等S&P 2025
- Ghostor: Toward a Secure Data-Sharing System from Decentralized TrustYuncong Hu, Sam Kumar, Raluca Ada PopaNSDI 2020 · 被引用 48 次
- End-to-End Encrypted Git ServicesYa-Nan Li, Yaqing Song, Qiang Tang, Moti YungCCS 2025 · 被引用 1 次
