From: Luca Di Carlo Date: Wed, 07 Oct 2026 19:19:02 GMT Subject: Re: git non-intrusive clone Message-ID: In-Reply-To: Hey, You are right, I've re-read the article that I had in mind, he downloads it as zip before, not as clone. `.git` is not cloned. Sorry for that. Thanks On Wed, Oct 7, 2026, at 20:54, D. Ben Knoble wrote: > I may have misunderstood, but… > > On Wed, Oct 7, 2026 at 4:40 AM Luca Di Carlo wrote: > > > > Hey everyone, > > I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks. > > I don't think a _clone_ can ship and enable hooks on its own. (I know > of at least one npm package that wants to install Git hooks when you > run "npm i"/"npm ci", though… turn on "ignore-scripts" for that.) That > is, you should be very careful executing anything from a cloned > repository you don't trust, but I don't think a clone can ship > executable hooks in a meaningful way. > > What *can* get you is an archive that includes ".git/", since it can > contain hooks that Git will execute (modulo safe.directory, I think, > but that typically doesn't apply in these situations). So: also be > careful extracting arbitrary archives! > > Maybe you had other security flaw in mind, or maybe someone else can > tell me how we fix this beyond "tell folks to be careful" (which I > agree doesn't scale well). > > -- > D. Ben Knoble > Luca