Re: Intricacies of submodules
- From
Martin Langhoff <martin.langhoff@gmail.com>
- Date
- Apr 17, 2008, 21:31 UTC
- Message-ID
- <46a038f90804171431q51215be8od41792293712ca9@mail.gmail.com>
- In-Reply-To
- <bd6139dc0804171427i6bf2813at719c8dec13bc225c@mail.gmail.com>
On Thu, Apr 17, 2008 at 6:27 PM, Sverre Rabbelier <alturin@gmail.com> wrote:
Show 7 quoted lines
> > > Because of that an in-tree '.gitconfig' would have no security risks > > > as long as it is not 'used' until after the clone. > > > > This is not true. A pre-commit hook or pre-checkout hook could be destructive. > > But, those won't be executed till after the review, so everything > would be good still, wouldn't it?
No. A local review can be quite "active", involving changing branches, moving patches around, and fixing sh*t up. The hooks available offer plenty of danger if the repo can set them and make them active:
$ ls .git/hooks/ applypatch-msg post-commit post-update pre-commit update commit-msg post-receive pre-applypatch pre-rebase
cheers,
m
-- martin.langhoff@gmail.com martin@laptop.org -- School Server Architect - ask interesting questions - don't get distracted with shiny stuff - working code first - http://wiki.laptop.org/go/User:Martinlanghoff