git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git non-intrusive clone

From
LCLuca Di Carlo <luca@dicarlo.email>
Date
Oct 7, 2026, 19:19 UTC
Message-ID
<d6dc70f6-f155-4a5a-b647-ac24b2b1ed37@app.fastmail.com>
In-Reply-To
<CALnO6CCTbWLn2rO9ASr+5K07vqkaWCx+H8NsCxaAMgHUYR=z5g@mail.gmail.com>

Hey, You are right, I've re-read the article that I had in mind, he downloads it as zip before, not as clone. `.git` is not cloned. Sorry for that. Thanks

On Wed, Oct 7, 2026, at 20:54, D. Ben Knoble wrote:
Show 26 quoted lines
> I may have misunderstood, but…
> 
> On Wed, Oct 7, 2026 at 4:40 AM Luca Di Carlo wrote:
> >
> > Hey everyone,
> > I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks.
> 
> I don't think a _clone_ can ship and enable hooks on its own. (I know
> of at least one npm package that wants to install Git hooks when you
> run "npm i"/"npm ci", though… turn on "ignore-scripts" for that.) That
> is, you should be very careful executing anything from a cloned
> repository you don't trust, but I don't think a clone can ship
> executable hooks in a meaningful way.
> 
> What *can* get you is an archive that includes ".git/", since it can
> contain hooks that Git will execute (modulo safe.directory, I think,
> but that typically doesn't apply in these situations). So: also be
> careful extracting arbitrary archives!
> 
> Maybe you had other security flaw in mind, or maybe someone else can
> tell me how we fix this beyond "tell folks to be careful" (which I
> agree doesn't scale well).
> 
> -- 
> D. Ben Knoble
> 
Luca
Previous: D. Ben KnobleNext: D. Ben Knoble
Message 3 of 5 in “git non-intrusive clone”
  1. Luca Di CarloOct 7, 2026
  2. D. Ben KnobleOct 7, 2026
  3. Luca Di CarloOct 7, 2026
  4. D. Ben KnobleOct 7, 2026
  5. Nico WilliamsOct 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.