{"thread":{"id":"45147","subject":"enhance git-add to avoid password being staged or committed?","startedAt":"2017-02-15T14:36:59Z","lastAt":"2017-02-15T21:26:15Z","messageCount":2,"participants":["ryenus","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"311652","messageId":"CAKkAvawFJwAcn_360O101vvtbUL3Cwfqx_8VLQg_PjWzFVwDVw@mail.gmail.com","threadId":"45147","inReplyTo":null,"subject":"enhance git-add to avoid password being staged or committed?","fromName":"ryenus","fromEmail":"ryenus@gmail.com","sentAt":"2017-02-15T14:36:32Z","receivedAt":"2017-02-15T14:36:59Z","isPatch":false,"sender":{"key":"ryenus@gmail.com","avatar":"https://avatars.githubusercontent.com/u/610161?v=4"},"body":"This can be an optional feature, once enabled, git-add would check the\nhunk(s) to stage for sensitive information, such as passwords, secret\ntokens, then ask the user for confirmation.\n\nThe implementation for secret detection could be regexp pattern(s),\nand/or (trusted?) commands\n\nAlternative solutions might be hooks during commit, push or recieve,\nbut it should be the best to do this in the first place during git-add.\n\nThe context of this is the following HN discussion about passwords on\nGitHub: https://news.ycombinator.com/item?id=13650818\n"},{"id":"311674","messageId":"20170215212608.whrcgjfwycrrblx3@sigill.intra.peff.net","threadId":"45147","inReplyTo":"CAKkAvawFJwAcn_360O101vvtbUL3Cwfqx_8VLQg_PjWzFVwDVw@mail.gmail.com","subject":"Re: enhance git-add to avoid password being staged or committed?","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2017-02-15T21:26:09Z","receivedAt":"2017-02-15T21:26:15Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Wed, Feb 15, 2017 at 10:36:32PM +0800, ryenus wrote:\n\n> This can be an optional feature, once enabled, git-add would check the\n> hunk(s) to stage for sensitive information, such as passwords, secret\n> tokens, then ask the user for confirmation.\n> \n> The implementation for secret detection could be regexp pattern(s),\n> and/or (trusted?) commands\n> \n> Alternative solutions might be hooks during commit, push or recieve,\n> but it should be the best to do this in the first place during git-add.\n\nThere are already hooks for commit and receive to catch things locally\nand at publishing time, respectively. It's possible that an \"add\" hook\ncould be more useful, but I'd be a lot more convinced if people were\nactively doing secret-detection in their commit hooks and had some\nspecific complaint that could be addressed by having an \"add\" hook.\n\n-Peff\n"}]}