Re: [BUG] git-credential-libsecret writes secret to stdout on store
- From
- Phillip Wood <phillip.wood123@gmail.com>
- Date
- Apr 22, 2026, 13:13 UTC
- Message-ID
- <fe75e0a5-1a87-4515-b02b-bfbef0366aaf@gmail.com>
- In-Reply-To
- <0b2370ed-f3e1-4011-8a2c-8da539759881@gmail.com>
On 22/04/2026 06:49, Mantas Mikulėnas wrote:
Show 10 quoted lines
>> 2. The direct-invocation pattern shows up widely in distro docs, >> StackOverflow answers, and automation scripts -- empirically the >> "internal protocol" boundary is porous. Fixing the helper is one >> line; documenting the internal boundary across the ecosystem is >> not. >> >> If the preferred answer is instead "users should only use >> `git credential approve`", that would also work for me, but it may >> deserve a note in gitcredentials(7) to steer people away from the >> direct pattern -- the current docs don't actively discourage it.
Yes, users should be using "git credential", not be running the helpers directly. That's why the helpers are installed in a directory that is not in $PATH. gitcredentials(7) shows how to set the config setting used by "git credential", as far as I can see it does not suggest that users should be running the helpers directly.
Thanks
Phillip