Rich Freeman:
> 
> I suggest we just get git working in a fashion that is "good enough."

Sure, that's what I've been saying. Otherwise I'd propose to remove
access for everyone and only grant project leads/reviewers direct push
access. But as said... we are not ready for something like that.

However, gpg signature verification is trivial to implement (and is
already) and starting with stricter policies is worth a try. Nothing of
that is really a big deal.

But... starting release-oriented strategies IS a big deal.

Reply via email to