gitsign VS github

Compare gitsign vs github and see what are their differences.

gitsign

Keyless Git signing using Sigstore (by sigstore)

github

Just a place to track issues and feature requests that I have for github (by isaacs)
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
gitsign github
10 30
899 2,146
0.7% -
9.1 3.0
3 days ago almost 3 years ago
Go
GNU General Public License v3.0 or later -
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

gitsign

Posts with mentions or reviews of gitsign. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-10-24.
  • Gittuf – a security layer for Git using some concepts introduced by TUF
    5 projects | news.ycombinator.com | 24 Oct 2023
    > does it also filter/escape ANSI Sequences in messages and author names?

    Not at present! Do you have a link or so I could use to familiarize myself? I'm curious if it'd fall within gittuf's scope.

    > does it block garbage collection?

    Nope, it doesn't. That said, the repository will have more objects, gittuf tracks additional objects through custom refs in `refs/gittuf/`.

    > how do you ensure that the developers are really the developers and there's no spoofing?

    At present, gittuf policies use signing keys. It doesn't rely on the commit metadata for author and committer but rather the commit's signature. We support GPG and Sigstore's gitsign [0] right now, and we want to support other signing mechanisms like SSH keys as well.

    [0] https://github.com/sigstore/gitsign

  • Signing Git Commits with Your SSH Key
    6 projects | news.ycombinator.com | 13 Sep 2022
    You may want to check out https://github.com/sigstore/gitsign! You can generate ephemeral x509 code signing certs for free using Sigstore.

    (disclosure: I'm a maintainer for gitsign)

  • A toolbox for a secure software supply chain
    1 project | news.ycombinator.com | 26 Aug 2022
    Def check out the gitsign project mentioned in the post: https://github.com/sigstore/gitsign
  • Enable Gitsign Today and Start Signing your Commits
    2 projects | dev.to | 25 Aug 2022
    Gitsign offers a keyless commit signing implementation based on OIDC, which is an identity layer built on top of the OAuth 2.0 framework. Gitsign supports verifying your identity either through GitHub, Microsoft, or a Google account.
  • SSH commit verification now supported
    4 projects | news.ycombinator.com | 23 Aug 2022
    Shameless plug for the gitsign project in sigstore: https://github.com/sigstore/gitsign

    This isn't supported by GitHub yet but we're hopefully working towards that too.

  • sigstore/gitsign: Keyless Git signing using Sigstore
    1 project | /r/devopsish | 24 Jun 2022
  • Keyless Git signing with Sigstore!
    2 projects | /r/kubernetes | 23 Jun 2022
  • Gitsign
    7 projects | news.ycombinator.com | 9 Jun 2022
    We used to actually run an RFC3161 timestamp server in addition to the transparency log but recently turned it down because no one was using it. I'd like to bring it back for stuff like this.

    https://github.com/sigstore/gitsign/issues/22

    1 project | /r/devopspro | 16 May 2022

github

Posts with mentions or reviews of github. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-12-03.
  • How I Fixed GitHub's Repo Traffic Insights πŸ› οΈ πŸ“Š
    3 projects | dev.to | 3 Dec 2023
    While looking for solutions, I realized that many developers face similar challenges. This issue is widely discussed, particularly in a GitHub thread: Track traffic to GitHub repo longer than 14 days #399.
  • Organizing Multiple Git Identities
    6 projects | news.ycombinator.com | 16 Oct 2023
    Probably the older email address is still the primary one for the GitHub account.

    GitHub took it upon themselves to change email addresses and author names when merging via the UI buttons like "Squash and Merge" in 2018 and then again in 2019. See <https://github.com/isaacs/github/issues/1368> for the tedious details.

    Essentially the post-2019 behaviour seems to be that where possible with "Squash and Merge" they will set noreply@github as the committer so that they can sign the merged commit themselves, and set author name & email to what they have recorded for the GH account involved (and the signature is then a record that GH have verified that account's involvement).

    Personally I think it is shocking that they ignore the name and email address that the actual author of the commit has selected. This is both a violation of the author's intentions -- for example, you may set work and personal email addresses in different repositories as discussed here, but GitHub will rewrite them all to the same thing when other people press "Squash and Merge" on your pull requests -- and potentially a doxxing security risk.

    I have considered re-reporting this to GitHub via the newer community discussions or via support again, but given the extent to which they've ignored all such reports over the last five years it is hard to find the motivation to do so.

  • GitHub prevents crawling of repository's Wiki pages – no Google search
    1 project | news.ycombinator.com | 1 Sep 2023
  • How do Commercial Open Source Startups manage GitHub insights &gt; 14 days? Is everyone using a workaround? How are "unique" cloners and viewers kept track off?
    3 projects | /r/opensource | 25 May 2023
    However, there is a massive issue. Github by default truncates insights to t-14 days (where t = today). This is super annoying as there is a discontinuity in data. There is also an archived issue on Github regarding this. The issue has a whopping 119 comments and has been around for over 8 years now. Basically, from the discussions there - Data you don't persist today will be gone 14 days from now. And looks like Github hasn't done anything about it.
  • Reimplementing the Coreutils in a modern language (Rust)
    7 projects | news.ycombinator.com | 13 Feb 2023
    > Hi, people have made money using my code and I also don’t care

    looks like everyone's missing the point.

    > I understand this is upsetting to you

    Again, maybe I am on another level of comprehension, so I don't understanda why it is so hard for someone to get it, but I am not upset by that, at all.

    I simply know that those who think "it will be fine" are delusional and don't know what they are talking about!

    So I just will paste some link to relevant news here, maybe it will make things clearer.

    It includes the opinion of Antirez, father of one of the most successful OSS ever: Redis. Maybe his words will open your eyes and tear the veil of Maya.

    (spoiler ahead alert!)

    Basically you work for free and people don't even thank you and the maintainer ends up being doxed or blamed or pushed aside and in the long term the only solution to keep sanity is to resign

    https://www.jeffgeerling.com/blog/2022/burden-open-source-ma...

    https://www.theregister.com/2022/01/13/opensource_apacheplc4...

    https://nolanlawson.com/2017/03/05/what-it-feels-like-to-be-...

    https://old.reddit.com/r/linux/comments/z14tt2/reason_why_op...

    https://github.com/isaacs/github/issues/167

    http://web.archive.org/web/20221217180915/http://antirez.com...

  • Git archive checksums may change
    10 projects | news.ycombinator.com | 30 Jan 2023
    I don't know what the fuss is all about. It was publicly known that Github was breaking automatic git archives consistency for many years. Here is a bug on a project to stop relying on fake github archives (as opposed to stable git-archive(1)):

    https://bugzilla.tianocore.org/show_bug.cgi?id=3099

    At some point it was impossible to go a few weeks (or even days) without a github archive change (depending on which part of the "CDN" you hit), I guess they must have stabilized it at some point. Here is an old issue before GitHub had a community issue tracker:

    https://github.com/isaacs/github/issues/1483

  • Keeping a Project Bisectable
    3 projects | news.ycombinator.com | 4 Aug 2022
    Hello, I see you stepped on my favourite personal soapbox! :)

    https://github.com/isaacs/github/issues/1017

    I really, really like semi-linear branching/merging. I.e. always rebase-merging, but with a merge commit.

    Reasons, in comparison to Github's "rebase merge" which doesn't produce a merge commit:

    1. It makes it clear which commits were part of one PR

    2. It makes it clear who did the merge

    3. It's okay to not have every commit build. but the one being merged will.

    4. Still pretty bisectable. You'll narrow things down at least to the PR that caused an issue, and from there it's usually quite simple.

    5. Looks very tidy in gitk & Co

  • Documenting My Work Again: hypothes.is
    3 projects | /r/Crostini | 8 Jul 2022
    Not to say that the feature isn't coming to FOSS git services.. Just that even proprietary organizations have had issues with taking a while to implement them.
  • Keyless Git signing with Sigstore!
    2 projects | /r/kubernetes | 23 Jun 2022
    Oh this is cool actually! Nice! One of the grievances I have with github commit signing is this issue https://github.com/isaacs/github/issues/1099
  • Attempting to transfer a repository upon resigning from a company (warning I'm a noob)
    1 project | /r/github | 17 Jun 2022
    In addition, you probably want to read this discussion. https://github.com/isaacs/github/issues/1138

What are some alternatives?

When comparing gitsign and github you can also consider the following projects:

smimesign - An S/MIME signing utility for use with Git

Custom-Scenes - Please go to https://github.com/Notexe/h3-custom-scenes instead. Hitman 3 custom scene experimentation using ResourceTool + QuickEntity + simple-mod-framework + RPKG Tool

git-ts - Git TimeStamp Utility

Signal-Server - Server supporting the Signal Private Messenger applications on Android, Desktop, and iOS

SignTools - βœ’ A free, self-hosted platform to sideload iOS apps without a computer

git2html - github clone of http://hssl.cs.jhu.edu/~neal/git2html/

community - Public feedback discussions for: GitHub Mobile, GitHub Discussions, GitHub Codespaces, GitHub Sponsors, GitHub Issues and more!

Monocypher - An easy to use, easy to deploy crypto library

cargo-vet - supply-chain security for Rust

create-branch-from-issue - Creating branch from issue on Github, tampermonkey script

vouch - A multi-ecosystem package code review system.

mollyim-android - Enhanced and security-focused fork of Signal.