{"thread":{"id":"66481","subject":"git non-intrusive clone","startedAt":"2026-10-07T08:40:13Z","lastAt":"2026-10-07T20:26:28Z","messageCount":5,"participants":["Luca Di Carlo","D. Ben Knoble","Nico Williams"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"554359","messageId":"e30c5b13-5ca3-43d1-a87a-d807b71bad7b@app.fastmail.com","threadId":"66481","inReplyTo":null,"subject":"git non-intrusive clone","fromName":"Luca Di Carlo","fromEmail":"luca@dicarlo.email","sentAt":"2026-10-07T08:40:13Z","receivedAt":"2026-10-07T08:40:13Z","isPatch":false,"sender":{"key":"luca@dicarlo.email","avatar":null},"body":"Hey everyone,\nI am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks. \nI wonder if we could have a \n`git clone --non-intrusive ...` \nThat would disable all git settings set within the repo. \nMaybe by adding a `.nogitconfig` file or something, so that the developers remember that because of this file, he cannot push or fetch, or use any `.git/` defined stuff. \n\nI hope this is the right channel, sorry if it's not. \n\nThank you for all your work,\nKind regards\nLuca\n\nCordialement\nLuca Di Carlo \n\n"},{"id":"554409","messageId":"CALnO6CCTbWLn2rO9ASr+5K07vqkaWCx+H8NsCxaAMgHUYR=z5g@mail.gmail.com","threadId":"66481","inReplyTo":"e30c5b13-5ca3-43d1-a87a-d807b71bad7b@app.fastmail.com","subject":"Re: git non-intrusive clone","fromName":"D. Ben Knoble","fromEmail":"ben.knoble@gmail.com","sentAt":"2026-10-07T18:54:02Z","receivedAt":"2026-10-07T18:54:02Z","isPatch":false,"sender":{"key":"ben.knoble@gmail.com","avatar":"https://avatars.githubusercontent.com/u/22802209?v=4"},"body":"I may have misunderstood, but…\n\nOn Wed, Oct 7, 2026 at 4:40 AM Luca Di Carlo <luca@dicarlo.email> wrote:\n>\n> Hey everyone,\n> I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks.\n\nI don't think a _clone_ can ship and enable hooks on its own. (I know\nof at least one npm package that wants to install Git hooks when you\nrun \"npm i\"/\"npm ci\", though… turn on \"ignore-scripts\" for that.) That\nis, you should be very careful executing anything from a cloned\nrepository you don't trust, but I don't think a clone can ship\nexecutable hooks in a meaningful way.\n\nWhat *can* get you is an archive that includes \".git/\", since it can\ncontain hooks that Git will execute (modulo safe.directory, I think,\nbut that typically doesn't apply in these situations). So: also be\ncareful extracting arbitrary archives!\n\nMaybe you had other security flaw in mind, or maybe someone else can\ntell me how we fix this beyond \"tell folks to be careful\" (which I\nagree doesn't scale well).\n\n-- \nD. Ben Knoble\n\n"},{"id":"554413","messageId":"d6dc70f6-f155-4a5a-b647-ac24b2b1ed37@app.fastmail.com","threadId":"66481","inReplyTo":"CALnO6CCTbWLn2rO9ASr+5K07vqkaWCx+H8NsCxaAMgHUYR=z5g@mail.gmail.com","subject":"Re: git non-intrusive clone","fromName":"Luca Di Carlo","fromEmail":"luca@dicarlo.email","sentAt":"2026-10-07T19:19:02Z","receivedAt":"2026-10-07T19:19:02Z","isPatch":false,"sender":{"key":"luca@dicarlo.email","avatar":null},"body":"Hey,\nYou are right, I've re-read the article that I had in mind, he downloads it as zip before, not as clone.\n`.git` is not cloned. \nSorry for that. \nThanks\n\nOn Wed, Oct 7, 2026, at 20:54, D. Ben Knoble wrote:\n> I may have misunderstood, but…\n> \n> On Wed, Oct 7, 2026 at 4:40 AM Luca Di Carlo wrote:\n> >\n> > Hey everyone,\n> > I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks.\n> \n> I don't think a _clone_ can ship and enable hooks on its own. (I know\n> of at least one npm package that wants to install Git hooks when you\n> run \"npm i\"/\"npm ci\", though… turn on \"ignore-scripts\" for that.) That\n> is, you should be very careful executing anything from a cloned\n> repository you don't trust, but I don't think a clone can ship\n> executable hooks in a meaningful way.\n> \n> What *can* get you is an archive that includes \".git/\", since it can\n> contain hooks that Git will execute (modulo safe.directory, I think,\n> but that typically doesn't apply in these situations). So: also be\n> careful extracting arbitrary archives!\n> \n> Maybe you had other security flaw in mind, or maybe someone else can\n> tell me how we fix this beyond \"tell folks to be careful\" (which I\n> agree doesn't scale well).\n> \n> -- \n> D. Ben Knoble\n> \n\nLuca\n\n"},{"id":"554417","messageId":"CALnO6CA5tY5Ebw5JyA8c-e00PqLcXMAijA5VF6DrPJNDCX=raA@mail.gmail.com","threadId":"66481","inReplyTo":"d6dc70f6-f155-4a5a-b647-ac24b2b1ed37@app.fastmail.com","subject":"Re: git non-intrusive clone","fromName":"D. Ben Knoble","fromEmail":"ben.knoble@gmail.com","sentAt":"2026-10-07T19:50:43Z","receivedAt":"2026-10-07T19:50:43Z","isPatch":false,"sender":{"key":"ben.knoble@gmail.com","avatar":"https://avatars.githubusercontent.com/u/22802209?v=4"},"body":"On Wed, Oct 7, 2026 at 3:20 PM Luca Di Carlo <luca@dicarlo.email> wrote:\n>\n> Hey,\n> You are right, I've re-read the article that I had in mind, he downloads it as zip before, not as clone.\n> `.git` is not cloned.\n> Sorry for that.\n> Thanks\n\n[we bottom-post here ;)]\n\nNo worries! I think in the past Git has said \"that's not really part\nof our security model\", but I don't have any authoritative references.\n\nStill, definitely worth having the conversation, and I'm glad we\nfigured it out together. I'm still somewhat interested in what we can\ndo besides \"try to tell folks not to blindly trust downloaded files\"…\nbut that's never going to stop being bad advice :)\n\n-- \nD. Ben Knoble\n\n"},{"id":"554420","messageId":"asaq9MaTvtuFyrpm@ubby","threadId":"66481","inReplyTo":"CALnO6CA5tY5Ebw5JyA8c-e00PqLcXMAijA5VF6DrPJNDCX=raA@mail.gmail.com","subject":"Re: git non-intrusive clone","fromName":"Nico Williams","fromEmail":"nico@cryptonector.com","sentAt":"2026-10-07T20:26:28Z","receivedAt":"2026-10-07T20:26:28Z","isPatch":false,"sender":{"key":"nico@cryptonector.com","avatar":null},"body":"On Wed, Oct 07, 2026 at 03:50:43PM -0400, D. Ben Knoble wrote:\n> Still, definitely worth having the conversation, and I'm glad we\n> figured it out together. I'm still somewhat interested in what we can\n> do besides \"try to tell folks not to blindly trust downloaded files\"…\n> but that's never going to stop being bad advice :)\n\nThere have been horror stories about phishing via fake interviews.\nThere is no easy way to ascertain the trustworthiness of such code.\nJust don't run that code.  Use a hosted VM service for this or insist\nthat they use a code pad type web application -- that they don't use\nthose is a red flag.\n\nNico\n-- \n\n"}]}