git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Why isn't hook file cloned to bared repository ?

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Mar 4, 2009, 10:04 UTC
Message-ID
<alpine.DEB.1.00.0903041103270.8549@intel-tinevez-2-302>
In-Reply-To
<3e8340490903032213u56734301o39c9d00633410fd5@mail.gmail.com>
Hi,
On Wed, 4 Mar 2009, Bryan Donlan wrote:
Show 15 quoted lines
> On Wed, Mar 4, 2009 at 12:40 AM, Emily Ren <lingyan.ren@gmail.com> wrote:
>
> > I added file "update" in my git repository my_repo/.git/hooks/,  then
> > I run command "git clone --bare my_repo" to generate a bared
> > repository my_repo.git. But there's no update in my_repo.git/hooks.
> >
> > Do you know why ?
> 
> Because allowing code from an untrusted third-party repository to be
> executed automatically without giving a chance to examine it is not a
> very good idea from a security standpoint. In addition, hooks are
> often not of interest to the person cloning the repository. Because of
> these reasons, git clone will not copy hooks from the source
> repository (for consistency, this is the case even when the source is
> local).

I might add that hooks are not part of the repository. They are not versioned, for example.

Having said that, nothing prevents you from committing a set of example hooks and a script to install them, and tell your users that they may install default hooks using that script. I do that for one of my projects.

Ciao, Dscho

Previous: Bryan Donlan
Message 3 of 3 in “Why isn't hook file cloned to bared repository ?”
  1. Emily RenMar 4, 2009
  2. Bryan DonlanMar 4, 2009
  3. Johannes SchindelinMar 4, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.