Re: git non-intrusive clone
- From
- Luca Di Carlo <luca@dicarlo.email>
- Date
- Oct 7, 2026, 19:19 UTC
- Message-ID
- <d6dc70f6-f155-4a5a-b647-ac24b2b1ed37@app.fastmail.com>
- In-Reply-To
- <CALnO6CCTbWLn2rO9ASr+5K07vqkaWCx+H8NsCxaAMgHUYR=z5g@mail.gmail.com>
Hey, You are right, I've re-read the article that I had in mind, he downloads it as zip before, not as clone. `.git` is not cloned. Sorry for that. Thanks
On Wed, Oct 7, 2026, at 20:54, D. Ben Knoble wrote:
Show 26 quoted lines
> I may have misunderstood, but… > > On Wed, Oct 7, 2026 at 4:40 AM Luca Di Carlo wrote: > > > > Hey everyone, > > I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks. > > I don't think a _clone_ can ship and enable hooks on its own. (I know > of at least one npm package that wants to install Git hooks when you > run "npm i"/"npm ci", though… turn on "ignore-scripts" for that.) That > is, you should be very careful executing anything from a cloned > repository you don't trust, but I don't think a clone can ship > executable hooks in a meaningful way. > > What *can* get you is an archive that includes ".git/", since it can > contain hooks that Git will execute (modulo safe.directory, I think, > but that typically doesn't apply in these situations). So: also be > careful extracting arbitrary archives! > > Maybe you had other security flaw in mind, or maybe someone else can > tell me how we fix this beyond "tell folks to be careful" (which I > agree doesn't scale well). > > -- > D. Ben Knoble >
Luca