git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: I don't want the .git directory next to my code.

From
Wincent Colaiuta <win@wincent.com>
Date
Jan 17, 2008, 10:34 UTC
Message-ID
<6D3239B9-FFE2-48AB-A127-E394D2FC8130@wincent.com>
In-Reply-To
<478EEAC4.2010006@talkingspider.com>
El 17/1/2008, a las 6:42, Mike escribió:
Show 25 quoted lines
> Linus Torvalds wrote:
>
>> Some people don't split this up, and they tend to make horrible  
>> horrible mistakes, like checking in the *results* of the post- 
>> processing too (ie binary result blobs that can be regenerated from  
>> the other files), because they don't make a clear separation  
>> between the parts they do development on, and the end result.
>
> Honestly, I think your mode of thinking is centered around compiled  
> languages and linux app(/kernel) development.  The web app  
> development/deployment model is very different.
>
> With PHP, Python, and Ruby, the development is the deployment.  The  
> source is the output.  You can't develop web apps in those languages  
> unless the source files you're working on are under the doc root of  
> your development server.   "the parts they do development on" and  
> "the end result" *are* the same files.
>
> The "development server -> staging server -> live
> server" model has been around in common use for as long as web
> applications have. In fact, the term "deployment" falls apart here.  
> From my web app developer perspective, the deployment is what lands  
> on the live server.  For your git perspective, the "deployment" may  
> mean the .../docroot/php directory for the development server (where  
> our app code lives).

I don't think so. Most people I speak with doing web app development develop locally and deploy remotely.

> There's a fundamental "best practice" of web development being  
> violated here- keep your docroots clean, only put stuff in them that  
> should go live (or should eventually go live when ready).  Other  
> files should not live under docroot.

Assuming you're using Apache, why don't you just add an .htaccess file to your repo at the top level which instructs Apache to forbid all access to .git and its contents? If Apache is so broken that you can't trust Apache to forbid access in those circumstances, then you can't trust it to not allow access to arbitrary paths on your filesystem outside of your doc root anyway.

Cheers, Wincent

Previous: Kris ShannonNext: Jeff King
Message 15 of 65 in “I don't want the .git directory next to my code.”
  1. MikeJan 16, 2008
  2. Randal L. SchwartzJan 16, 2008
  3. MikeJan 16, 2008
  4. David SymondsJan 16, 2008
  5. MikeJan 16, 2008
  6. SeanJan 16, 2008
  7. MikeJan 16, 2008
  8. Neil MacnealeJan 16, 2008
  9. MikeJan 16, 2008
  10. Johannes SchindelinJan 16, 2008
  11. Linus TorvaldsJan 16, 2008
  12. Linus TorvaldsJan 16, 2008
  13. MikeJan 17, 2008
  14. Kris ShannonJan 17, 2008
  15. Wincent ColaiutaJan 17, 2008
  16. Jeff KingJan 17, 2008
  17. Linus TorvaldsJan 17, 2008
  18. Johannes SchindelinJan 17, 2008
  19. Linus TorvaldsJan 17, 2008
  20. Johannes SchindelinJan 17, 2008
  21. MikeJan 17, 2008
  22. Johannes SchindelinJan 17, 2008
  23. MikeJan 17, 2008
  24. Johannes SchindelinJan 17, 2008
  25. MikeJan 17, 2008
  26. Johannes SchindelinJan 17, 2008
  27. MikeJan 17, 2008
  28. Johannes SchindelinJan 17, 2008
  29. David SymondsJan 18, 2008
  30. Russ DillJan 22, 2008
  31. Martin LanghoffJan 17, 2008
  32. Andreas EricssonJan 18, 2008
  33. Junio C HamanoJan 16, 2008
  34. Ping YinJan 17, 2008
  35. Linus TorvaldsJan 17, 2008
  36. Dan McGeeJan 16, 2008
  37. MikeJan 16, 2008
  38. Mike KrierJan 16, 2008
  39. MikeJan 16, 2008
  40. Nguyen Thai Ngoc DuyJan 16, 2008
  41. David SymondsJan 16, 2008
  42. MikeJan 16, 2008
  43. Daniel BarkalowJan 16, 2008
  44. Luke LuJan 16, 2008
  45. MikeJan 16, 2008
  46. Sam VilainJan 17, 2008
  47. Daniel BarkalowJan 16, 2008
  48. MikeJan 16, 2008
  49. Johannes SchindelinJan 16, 2008
  50. Bert WesargJan 16, 2008
  51. Wayne DavisonJan 16, 2008
  52. Matthieu MoyJan 16, 2008
  53. Johannes SchindelinJan 16, 2008
  54. Bill LearJan 16, 2008
  55. Matthieu MoyJan 16, 2008
  56. Johannes SchindelinJan 16, 2008
  57. Junio C HamanoJan 16, 2008
  58. Johannes SchindelinJan 16, 2008
  59. Matthieu MoyJan 16, 2008
  60. Johannes SchindelinJan 16, 2008
  61. Jakub NarebskiJan 16, 2008
  62. Brian DowningJan 17, 2008
  63. Randal L. SchwartzJan 17, 2008
  64. Martin LanghoffJan 17, 2008
  65. Randal L. SchwartzJan 17, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.