git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Fetching SHA id's instead of named references?

From
KLKlas Lindberg <klas.lindberg@gmail.com>
Date
Apr 6, 2009, 12:41 UTC
Message-ID
<33f4f4d70904060541s6dfb7e8ctf50f5e8a872ae1c@mail.gmail.com>
In-Reply-To
<alpine.DEB.1.00.0904061431020.6619@intel-tinevez-2-302>
Hello

Thank you, but I don't understand the answer. If I mistakenly publish a tree that contains secrets and someone manages to fetch against it before I correct the mistake; how does the limitation to only fetch named references help me???

By the way: I don't use push. I'd be perfectly happy if just fetch supported SHA key references.

BR / Klas

On Mon, Apr 6, 2009 at 2:33 PM, Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:

Show 18 quoted lines
> Hi,
>
> On Mon, 6 Apr 2009, Klas Lindberg wrote:
>
>> Is there a way to fetch based on SHA id's instead of named references?
>
> No, out of security concerns;  imagine you included some proprietary
> source code by mistake, and undo the damage by forcing a push with a
> branch that does not have the incriminating code.  Usually you do not
> control the garbage-collection on the server, yet you still do not want
> other people to fetch "by SHA-1".
>
> BTW this is really a strong reason not to use HTTP push in such
> environments.
>
> Ciao,
> Dscho
>
Previous: Johannes SchindelinNext: Johannes Schindelin
Message 3 of 15 in “Fetching SHA id's instead of named references?”
  1. Klas LindbergApr 6, 2009
  2. Johannes SchindelinApr 6, 2009
  3. Klas LindbergApr 6, 2009
  4. Johannes SchindelinApr 6, 2009
  5. Dmitry PotapovApr 6, 2009
  6. Matthieu MoyApr 6, 2009
  7. Klas LindbergApr 6, 2009
  8. Finn Arne GangstadApr 6, 2009
  9. Shawn O. PearceApr 6, 2009
  10. Klas LindbergApr 6, 2009
  11. Nicolas PitreApr 6, 2009
  12. Klas LindbergApr 6, 2009
  13. Nicolas PitreApr 7, 2009
  14. Klas LindbergApr 8, 2009
  15. Nicolas PitreApr 8, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.