Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

what mitigations do you use to protect systems that automatically updated after every git push?


Don't auto-update production like that? If a change will affect all users,manually review it and as another commenter said,gpg signatures. Have every prod commiter use mfa too.


I have seen a lot of people describe their continuous delivery where the code is checked in and moves into production after passing tests. I wasn't sure if they had a way to deal with this type of issue or I am misunderstanding their process somehow. I


Would GPG signatures suffice?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: