On omitting commits and committing omissions: Preventing git metadata tampering that (re) introduces software vulnerabilities

Home / Publications / On omitting commits and committing omissions: Preventing git metadata tampering that (re) introduces software vulnerabilities

Santiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, and Justin Cappos

Metadata manipulation attacks represent a new threat class directed against Version Control Systems, such as the popular Git. This type of attack provides inconsistent views of a repository state to different developers, and deceives them into performing unintended operations with often negative consequences.