Re: git non-intrusive clone
- From
D. Ben Knoble <ben.knoble@gmail.com>
- Date
- Oct 7, 2026, 18:54 UTC
- Message-ID
- <CALnO6CCTbWLn2rO9ASr+5K07vqkaWCx+H8NsCxaAMgHUYR=z5g@mail.gmail.com>
- In-Reply-To
- <e30c5b13-5ca3-43d1-a87a-d807b71bad7b@app.fastmail.com>
I may have misunderstood, but…
On Wed, Oct 7, 2026 at 4:40 AM Luca Di Carlo <luca@dicarlo.email> wrote:
> > Hey everyone, > I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks.
I don't think a _clone_ can ship and enable hooks on its own. (I know of at least one npm package that wants to install Git hooks when you run "npm i"/"npm ci", though… turn on "ignore-scripts" for that.) That is, you should be very careful executing anything from a cloned repository you don't trust, but I don't think a clone can ship executable hooks in a meaningful way.
What *can* get you is an archive that includes ".git/", since it can contain hooks that Git will execute (modulo safe.directory, I think, but that typically doesn't apply in these situations). So: also be careful extracting arbitrary archives!
Maybe you had other security flaw in mind, or maybe someone else can tell me how we fix this beyond "tell folks to be careful" (which I agree doesn't scale well).
-- D. Ben Knoble