4 ms·
I'm curious, what security risk does static content could pose by serving the .git ?
by hdra 13y ago
I'm curious, what security risk does static content could pose by serving the .git ?
- pyre 13y agoOff the top of my head, if you use an email (to commit) that you don't want the outside world to see, now it's exposed.
- calpaterson 13y agoIf you don't expect your source code to be made public and don't take care to keep secrets out of it, then you will be surprised when attackers have (for example) your cookie signing key. I know checking secrets into source code is already a bad practice, but accidental publication takes bad practice and makes it a security hole.
- drdaeman 13y agoParent post was asking about static content, not dynamic. No code to keep secret.