-
Notifications
You must be signed in to change notification settings - Fork 229
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Harden 'safe-expunging-process' #1135
Comments
More a follow up question about the current text:
I'm trying to understand the "without leaving a record" requirement. Would we have no trace of an object whatsoever? As in, not even its git ID / digest? |
I think part of the desire is to not call undue attention to the removal, which might be either especially important given the distributed nature of git (folks may have their own copy that has the removed content) or completely useless given the distributed nature of git (folks can just diff the things). Given the two extremes I think it's hard to actually say and perhaps we should leave that part up to the implementors. Let me make a proposal. |
fixes slsa-framework#1135 Hardens the 'safe-expunging-process' by: 1. Suggesting that SCSs should document and log changes when possible. 2. SCSs should use multi-party approval when possible Also clarifies that some of these changes may need to be kept private to comply with local laws. Signed-off-by: Tom Hennen <[email protected]>
fixes slsa-framework#1135 Hardens the 'safe-expunging-process' by: 1. Suggesting that SCSs should document and log changes when possible. 2. SCSs should use multi-party approval when possible Also clarifies that some of these changes may need to be kept private to comply with local laws. Signed-off-by: Tom Hennen <[email protected]>
fixes #1135 Hardens the 'safe-expunging-process' by: 1. Suggesting that SCSs should document and log changes when possible. 2. SCSs should use multi-party approval when possible Also clarifies that some of these changes may need to be kept private to comply with local laws. --------- Signed-off-by: Tom Hennen <[email protected]> Signed-off-by: Tom Hennen <[email protected]> Co-authored-by: Zachariah Cox <[email protected]> Co-authored-by: Aditya Sirish <[email protected]> Co-authored-by: Marcela Melara <[email protected]>
In #1094 (comment) @marcelamelara said
Let's make sure we're happy with this process before release.
The text was updated successfully, but these errors were encountered: