3 ms·
It certainly would, however like another comment I replied to ITT security doesn't have to be either-or it can be "do all the secure things". I.e. * No secret
by bbcbasic 11y ago
It certainly would, however like another comment I replied to ITT security doesn't have to be either-or it can be "do all the secure things".
I.e.
* No secrets in your repo
* Only copy to the server what you need (and automate this)
* Add conditions to your web server to not serve up .git, in-case the previous two checks failed.
When working in teams I think having additional checks and balances and not one 'perfect solution' is vital.
- danieltillett 11y agoExtremely good point - we should always aim for security in depth and especially don’t rely on people not doing stupid things, because if it is possible then someone will at some point.