git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: enhance git-add to avoid password being staged or committed?

From
Jeff King <peff@peff.net>
Date
Feb 15, 2017, 21:26 UTC
Message-ID
<20170215212608.whrcgjfwycrrblx3@sigill.intra.peff.net>
In-Reply-To
<CAKkAvawFJwAcn_360O101vvtbUL3Cwfqx_8VLQg_PjWzFVwDVw@mail.gmail.com>
On Wed, Feb 15, 2017 at 10:36:32PM +0800, ryenus wrote:
Show 9 quoted lines
> This can be an optional feature, once enabled, git-add would check the
> hunk(s) to stage for sensitive information, such as passwords, secret
> tokens, then ask the user for confirmation.
> 
> The implementation for secret detection could be regexp pattern(s),
> and/or (trusted?) commands
> 
> Alternative solutions might be hooks during commit, push or recieve,
> but it should be the best to do this in the first place during git-add.

There are already hooks for commit and receive to catch things locally and at publishing time, respectively. It's possible that an "add" hook could be more useful, but I'd be a lot more convinced if people were actively doing secret-detection in their commit hooks and had some specific complaint that could be addressed by having an "add" hook.

-Peff
Previous: ryenus
Message 2 of 2 in “enhance git-add to avoid password being staged or committed?”
  1. ryenusFeb 15, 2017
  2. Jeff KingFeb 15, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.