2 ms·
When merge commits involve conflict cleanup, they are very hard to debug (at least with standard tools like tig/gitk/diff; there might be something more advance
by generationP 4y ago
When merge commits involve conflict cleanup, they are very hard to debug (at least with standard tools like tig/gitk/diff; there might be something more advanced). I've seen lines of code disappear into nowhere in merge commits. You can only hope the conflicts were resolved well.
Even conflict-free merges can be scary -- you're trusting the system to find the right context. Of course, the same errors can happen on rebase, but at least the resulting commits can easily be inspected.
- georgyo 4y agoThe problems here come from the fact that a "merge" commit is just a normal commit with multiple parents. This means that anything can happen inside that merge commit, including add, remove, and modify all the code, even if not touched by a parent. Merge commits are good place for a malicious actor to hide changes.