git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Expanding Includes in .gitignore

From
APAaron Pelly <aaron@pelly.co>
Date
Oct 27, 2016, 22:17 UTC
Message-ID
<91e0f377-ecfd-ab0a-4f4b-8c0f762228aa@pelly.co>
In-Reply-To
<60a652f6-864e-bbda-7394-4751c92866b7@pelly.co>
On 28/10/16 10:55, Aaron Pelly wrote:
Show 8 quoted lines
> 2) I fetch a repo with a hostile ignore file. It includes files from
> $GIT_DIR/test-data/ssl/private or some such. Change. Don't pay
> attention. Commit. Push. Problems if my test data comes from production.
> 
> Is this mitigated currently?
> 
> Not that git should be an enabler, but surely it falls on the user of
> untrusted software to ensure their own security?
Balls, I meant $GIT_WORK_TREE not $GIT_DIR
Previous: Aaron PellyNext: Jeff King
Message 23 of 24 in “Expanding Includes in .gitignore”
  1. Aaron PellyOct 27, 2016
  2. Stefan BellerOct 27, 2016
  3. Aaron PellyOct 27, 2016
  4. Alexei LozovskyOct 27, 2016
  5. Aaron PellyOct 27, 2016
  6. Jeff KingOct 27, 2016
  7. Jacob KellerOct 27, 2016
  8. Aaron PellyOct 27, 2016
  9. Jeff KingOct 27, 2016
  10. Aaron PellyOct 27, 2016
  11. Jacob KellerOct 27, 2016
  12. Duy NguyenOct 30, 2016
  13. Aaron PellyOct 27, 2016
  14. Jeff KingOct 27, 2016
  15. Jeff KingOct 27, 2016
  16. Aaron PellyOct 27, 2016
  17. Aaron PellyOct 27, 2016
  18. Junio C HamanoOct 28, 2016
  19. Aaron PellyOct 28, 2016
  20. Duy NguyenOct 30, 2016
  21. Jeff KingOct 30, 2016
  22. Aaron PellyOct 27, 2016
  23. Aaron PellyOct 27, 2016
  24. Jeff KingOct 28, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.