Ensure verification of signed commits for new changes before merging
Identifying collaborators through signed commits prevents supply chain attacks
Risk Level: medium
Platform: Github
Spectral Rule ID: GH-HRD011
REMEDIATION
Enable signed commits.
SaaS:
In the repository setting on GitHub site:
- Go to 'Branches'.
- Go to 'Branch protection rule'.
- Click on 'Require signed commits' (should be marked).
Read more:
Updated about 1 year ago