git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [BUG] git-credential-libsecret writes secret to stdout on store

From
PWPhillip Wood <phillip.wood123@gmail.com>
Date
Apr 22, 2026, 13:13 UTC
Message-ID
<fe75e0a5-1a87-4515-b02b-bfbef0366aaf@gmail.com>
In-Reply-To
<0b2370ed-f3e1-4011-8a2c-8da539759881@gmail.com>
On 22/04/2026 06:49, Mantas Mikulėnas wrote:
Show 10 quoted lines
>> 2. The direct-invocation pattern shows up widely in distro docs,
>>    StackOverflow answers, and automation scripts -- empirically the
>>    "internal protocol" boundary is porous. Fixing the helper is one
>>    line; documenting the internal boundary across the ecosystem is
>>    not.
>>
>> If the preferred answer is instead "users should only use
>> `git credential approve`", that would also work for me, but it may
>> deserve a note in gitcredentials(7) to steer people away from the
>> direct pattern -- the current docs don't actively discourage it.

Yes, users should be using "git credential", not be running the helpers directly. That's why the helpers are installed in a directory that is not in $PATH. gitcredentials(7) shows how to set the config setting used by "git credential", as far as I can see it does not suggest that users should be running the helpers directly.

Thanks
Phillip
Previous: Mantas Mikulėnas
Message 4 of 4 in “[BUG] git-credential-libsecret writes secret to stdout on store”
  1. Lutz-Christian QuanderApr 21, 2026
  2. Mantas MikulėnasApr 21, 2026
  3. Mantas MikulėnasApr 22, 2026
  4. Phillip WoodApr 22, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.