Re: Is there any way to make hooks part of the repository?
- From
Junio C Hamano <gitster@pobox.com>
- Date
- May 2, 2012, 19:27 UTC
- Message-ID
- <7v1un2idt0.fsf@alter.siamese.dyndns.org>
- In-Reply-To
- <CAE1pOi3RZ+x7YcVZ-dLt70=wwRsvY9D6GQR-T+JZ9S7x8CFjPw@mail.gmail.com>
Hilco Wijbenga <hilco.wijbenga@gmail.com> writes:
Show 10 quoted lines
> On 1 May 2012 23:38, Matthieu Moy <Matthieu.Moy@grenoble-inp.fr> wrote: > ... >> Yes, but at least, you have the opportunity to examine the other places >> before they are ran. Hooks would be really, really nasty security-wise. >> For example, "git clone" does a checkout, so should probably run the >> checkout hooks. > > There is (or, rather, should be) absolutely no difference between code > changes and hook changes. Both would go through the same review > process.
Matthieu is *not* talking about auditing nastiness going into the project's repository; he is talking is about a chance to audit whatever comes from the project's repository that *could* potentially contain some nastiness before it causes harm to your working environment. In other words, not *having* to trust what is in the project's repository, but having a way to verify.
Read what he wrote again with that in mind, and you will understand his point.