The gittuf project is developing a cryptographic protection system for Git repositories.

The release of the gittuf project version 0.4 is now available, developing a hierarchical system for verifying the content of Git repositories, which minimizes risks in situations where individual developers with access to the repository have been compromised. Gittuf provides an additional layer of security to Git and a set of utilities for managing the keys of all developers with access to the repository, as well as setting access rules for branches, tags, and individual files. The project's code is written in Go and is distributed under the Apache 2.0 license. The project is actively developed and has the quality of an alpha release, suitable for experimentation but not yet ready for production implementations.

Information and artifacts that provide additional verification of changes made are stored in the Git object storage in a separate namespace specific to gittuf, allowing for backward compatibility with existing tools and services, including GitHub and GitLab. When using tools that do not support gittuf, the repository remains fully accessible, but the ability for enhanced verification of its integrity is limited. The gittuf architecture is based on proven elements of the TUF (The Update Framework) framework, which is used to protect update processes in projects such as Docker, Fuchsia, AGL (Automotive Grade Linux), and PyPI.

The verification model in gittuf is based on the application of a hierarchical system of trust distribution. The root of trust belongs to the repository owner, who can generate keys for development participants and define the rules under which these created keys can be used. Gittuf allows for the creation of flexible, granular rules that determine the permissions of each developer and the area of the repository where they can make changes. For example, a developer may be authorized to create tags, make changes to specific branches, or modify only certain files in the repository.

Developers and their changes are identified by keys and digital signatures. Gittuf allows for generating new keys, securely distributing keys, periodically rotating keys, revoking compromised keys, and managing access control lists (ACLs) and namespaces in Git repositories. Gittuf also maintains a reference log of all changes (RSL — Reference State Log), with integrity and backdating protection ensured through a tree structure known as a Merkle Tree — each branch verifies all underlying branches and nodes through tree hashing (having a final hash allows users to verify the correctness of the entire operation history and the accuracy of past states).

For verifying digital signatures of commits and tags, the repository owner generates and distributes public keys that are directly associated with the repository. Mechanisms for revocation and key replacement are employed to counteract the promotion of changes made by attackers after gaining access to the keys for creating digital signatures of individual developers. Keys have a limited lifespan and require constant renewal to protect against signatures generated by old keys.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster