All of lore.kernel.org
 help / color / mirror / Atom feed
* status on security of embedded repos?
@ 2022-09-03 18:48 Christoph Anton Mitterer
  2022-09-05 10:21 ` Johannes Schindelin
  0 siblings, 1 reply; 8+ messages in thread
From: Christoph Anton Mitterer @ 2022-09-03 18:48 UTC (permalink / raw)
  To: git

Hey.

A while ago there was this discussion about security issues with
respect to bare repos embedded in another repo[0][1].


I just wondered what's the status on this? Was that fixed in a way that
one can clone untrusted repos and navigate / use git commands within
them, without any risk… or is it still open?

Saw proposed patches like:
https://lore.kernel.org/git/pull.1261.git.git.1651861810633.gitgitgadget@gmail.com/#r

But it seems at least as of git 2.37.2, ther's no safe.barerepository
option, yet.


Also, couldn't the same happen for non-bare repos, too, or how is that
prevented for such?


Thanks,
Chris.


[0] https://lwn.net/ml/git/kl6lsfqpygsj.fsf@chooglen-macbookpro.roam.corp.google.com/
[1] https://lwn.net/Articles/892755/

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2022-09-09 18:32 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-09-03 18:48 status on security of embedded repos? Christoph Anton Mitterer
2022-09-05 10:21 ` Johannes Schindelin
2022-09-05 13:22   ` Christoph Anton Mitterer
2022-09-06 13:56     ` Johannes Schindelin
2022-09-07 14:05       ` Christoph Anton Mitterer
2022-09-08 16:56         ` Glen Choo
2022-09-09  0:05           ` Christoph Anton Mitterer
2022-09-09 18:26             ` Christoph Anton Mitterer

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.