git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git bundle format

From
Felipe Contreras <felipe.contreras@gmail.com>
Date
Nov 26, 2012, 20:20 UTC
Message-ID
<CAMP44s03QiO15jODBD4JO_JF8tCOT9OJG1tb4+r+L4dgPUOLFg@mail.gmail.com>
In-Reply-To
<871B6C10EBEFE342A772D1159D13208537ABF5AB@umechphj.easf.csd.disa.mil>

On Mon, Nov 26, 2012 at 8:24 PM, Pyeron, Jason J CTR (US) <jason.j.pyeron.ctr@mail.mil> wrote:

Show 12 quoted lines
> I may need to be nudged in a better direction, but please try to understand my intentions.
>
> I am facing a situation where I would like to use git bundle but at the same time inspect the contents to prevent a spillage[1].
>
> Given we have a public repository which was cloned on to a secret development repository. Now the developers do some work which should not be sensitive in any way and commit and push it to the secret repository.
>
> Now they want to release it out to the public. The current process is to review the text files to ensure that there is no "secret" sauce in there and then approve its release. This current process ignores the change tracking and all non-content is lost.
>
>
> In this situation we should assume that the bundle does not have any content which is already in the public repository, that is it has the minimum data to make it pass a git bundle verify from the public repositories point of view. We would then take the bundle and pipe it though the "git-bundle2text" program which would result in a "human" inspectable format as opposed to the packed format[2]. The security reviewer would then see all the information being released and with the help of the public repository see how the data changes the repository.
>
> Am I barking up the right tree?

Have you tried 'git fast-export'? The output is definitely not human inspectable, but should be relatively easy to parse to generate such a format. And instead of 'git bundle unbundle' you could use 'git fast-import'. or simply do the conversion in your script.

Cheers.
-- 
Felipe Contreras
Previous: Pyeron, Jason J CTR (US)Next: Pyeron, Jason J CTR (US)
Message 3 of 11 in “git bundle format”
  1. Pyeron, Jason J CTR (US)Nov 26, 2012
  2. Pyeron, Jason J CTR (US)Nov 26, 2012
  3. Felipe ContrerasNov 26, 2012
  4. Pyeron, Jason J CTR (US)Nov 26, 2012
  5. Felipe ContrerasNov 26, 2012
  6. Junio C HamanoNov 26, 2012
  7. Pyeron, Jason J CTR (US)Nov 26, 2012
  8. Stephen BashNov 26, 2012
  9. Pyeron, Jason J CTR (US)Nov 26, 2012
  10. Stephen BashNov 26, 2012
  11. Andrew ArdillNov 26, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.