The risks of embedded bare repositories in Git
The risks of embedded bare repositories in Git
Posted Apr 28, 2022 2:46 UTC (Thu) by pabs (subscriber, #43278)Parent article: The risks of embedded bare repositories in Git
Posted Apr 28, 2022 9:27 UTC (Thu)
by MrWim (subscriber, #47432)
[Link] (2 responses)
Generally speaking actions that feel safe should be made safe. Extracting a tarball, cloning a git repo, `cd`ing to a directory, `cat`ing a file all feel rather pedestrian - and if there are subtle security issues with them it's the software that needs to be fixed.
Posted Apr 28, 2022 10:04 UTC (Thu)
by geert (subscriber, #98403)
[Link] (1 responses)
Posted Apr 28, 2022 12:20 UTC (Thu)
by MrWim (subscriber, #47432)
[Link]
> It might come embedded inside a [...] tarball.
Posted Apr 28, 2022 11:13 UTC (Thu)
by k3ninho (subscriber, #50375)
[Link] (4 responses)
Oops.
K3n.
Posted Apr 28, 2022 14:19 UTC (Thu)
by MrWim (subscriber, #47432)
[Link] (3 responses)
Projects/linux
So then when you run `git status` in Projects/linux the hooks will be run, while if you run it in ~/Downloads/my-dodgy-project no hooks will be run.
Posted Apr 28, 2022 14:47 UTC (Thu)
by mathstuf (subscriber, #69389)
[Link] (1 responses)
Posted Apr 29, 2022 2:25 UTC (Fri)
by pabs (subscriber, #43278)
[Link]
Posted Apr 29, 2022 2:24 UTC (Fri)
by pabs (subscriber, #43278)
[Link]
The risks of embedded bare repositories in Git
The risks of embedded bare repositories in Git
The risks of embedded bare repositories in Git
The risks of embedded bare repositories in Git
Sure, give me the web address of the shell script to update the whitelist and I'll curl-pipe-sudo-bash it right away.
The risks of embedded bare repositories in Git
Projects/foo
Projects/bar
The risks of embedded bare repositories in Git
The risks of embedded bare repositories in Git
The risks of embedded bare repositories in Git
