git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Storing private config files in .git directory?

From
Jeff King <peff@peff.net>
Date
Jan 10, 2024, 11:08 UTC
Message-ID
<20240110110842.GD16674@coredump.intra.peff.net>
In-Reply-To
<xmqq34v7lmb3.fsf@gitster.g>
On Mon, Jan 08, 2024 at 10:20:00AM -0800, Junio C Hamano wrote:
Show 9 quoted lines
> Stefan Haller <lists@haller-berlin.de> writes:
> 
> > Our git client (lazygit) has a need to store per-repo config files that
> > override the global one, much like git itself. The easiest way to do
> > that is to store those in a .git/lazygit.cfg file, and I'm wondering if
> > there's any reason why this is a bad idea?
> 
> An obvious alternative is to have .lazygit directory next to .git directory
> which would give you a bigger separation, which can cut both ways.

Just to spell out one of those ways: unlike ".git", we will happily check out ".lazygit" from an untrusted remote repository. That may be a feature if you want to be able to share project-specific config, or it might be a terrible security vulnerability if lazygit config files can trigger arbitrary code execution.

-Peff
Previous: Junio C HamanoNext: Stefan Haller
Message 3 of 7 in “Storing private config files in .git directory?”
  1. Stefan HallerJan 7, 2024
  2. Junio C HamanoJan 8, 2024
  3. Jeff KingJan 10, 2024
  4. Stefan HallerJan 11, 2024
  5. Jeff KingJan 12, 2024
  6. Konstantin RyabitsevJan 8, 2024
  7. Marc BranchaudJan 8, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.