le-git-imate

A defense mechanism to mitigate attacks against web-based Git hosting services such as GitHub and GitLab. le-git-imate pioneers the ability to sign a web UI commit and thus create a true GPG-signed Git commit object in the browser.

Main features provided by le-git-imate:

  • Same security guarantees offered by Git's standard commit signing
  • No server-side changes on web-based Git hosting services
  • Preserve the ease of use of web UI
  • Minimal impact on users experience
  • Efficient (add no significant delay)

le-git-imate is an open source project hosted on GitHub. Use of the source code is governed by the Licensed under the Apache License, Version 2.0 that can be found at here.

For more technical details, please refer to our paper Towards adding verifiability to web-based Git repositories.

Install le-git-imate now