4 ms·
Perhaps it would be best if sensitive options such as the post-checkout hook could only be stored outside of the repository altogether. Given this vulnerability
by 0942v8653 8y ago
Perhaps it would be best if sensitive options such as the post-checkout hook could only be stored outside of the repository altogether. Given this vulnerability and the semi-recent .GiT/config vulnerability[0], I would not be surprised if other attack vectors are lurking under the surface.
Storing config data outside the repo would not be a foolproof solution, but it would probably make things a little safer. (Having the <repo_root>/.git folder has always felt a little bit "in-band" to me, and I don't like it.)
[0]: https://news.ycombinator.com/item?id=8769667 https://news.ycombinator.com/item?id=8769667