From: Aaron Pelly Date: Thu, 27 Oct 2016 22:17:26 GMT Subject: Re: Expanding Includes in .gitignore Message-ID: <91e0f377-ecfd-ab0a-4f4b-8c0f762228aa@pelly.co> In-Reply-To: <60a652f6-864e-bbda-7394-4751c92866b7@pelly.co> On 28/10/16 10:55, Aaron Pelly wrote: > 2) I fetch a repo with a hostile ignore file. It includes files from > $GIT_DIR/test-data/ssl/private or some such. Change. Don't pay > attention. Commit. Push. Problems if my test data comes from production. > > Is this mitigated currently? > > Not that git should be an enabler, but surely it falls on the user of > untrusted software to ensure their own security? Balls, I meant $GIT_WORK_TREE not $GIT_DIR