git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitfaq: document using stash import/export to sync working tree

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Jan 9, 2026, 20:11 UTC
Message-ID
<aWFg_VUZH5_ZqTix@fruit.crustytoothpaste.net>
In-Reply-To
<xmqqseceua9j.fsf@gitster.g>
On 2026-01-09 at 14:32:40, Junio C Hamano wrote:
Show 9 quoted lines
> "brian m. carlson" <sandals@crustytoothpaste.net> writes:
> 
> > Git 2.51 learned how to import and export stashes.  This is a
> > secure and robust way to transfer working tree states across machines
> 
> Here "secure" in "secure and robust" triggered my "huh?" sensor.  It
> is a robust way, but is there something particularly "secure" about
> it, other than "it is less likely to break your repository" in the
> sense that is already covered by "robust".

We know that sharing a working tree with different users is not secure because people can have things like hooks or config options that execute arbitrary code. Transferring stashes doesn't have that downside.

Considering that we used to explain that the only way to do this was to rsync the working tree across machines, this option is more secure than the previous option since it avoids any potential code execution. It also avoids syncing things like ignored `.env` files, which people often use to store secrets, since `git stash` doesn't transfer ignored files (but rsync often does).

But if you disagree and prefer to remove it, please feel free to edit the commit message before you merge to next, or let me know and I can send a v2 if you prefer.

-- 
brian m. carlson (they/them)
Toronto, Ontario, CA
Previous: Junio C HamanoNext: Junio C Hamano
Message 3 of 4 in “gitfaq: document using stash import/export to sync working tree”
  1. gitfaq: document using stash import/export to sync working treebrian m. carlson, Jan 9, 2026
  2. Junio C HamanoJan 9, 2026
  3. brian m. carlsonJan 9, 2026
  4. Junio C HamanoJan 10, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.