From: Junio C Hamano Date: Sat, 10 Jan 2026 01:56:00 GMT Subject: Re: [PATCH] gitfaq: document using stash import/export to sync working tree Message-ID: In-Reply-To: "brian m. carlson" writes: > On 2026-01-09 at 14:32:40, Junio C Hamano wrote: >> "brian m. carlson" writes: >> >> > Git 2.51 learned how to import and export stashes. This is a >> > secure and robust way to transfer working tree states across machines >> >> Here "secure" in "secure and robust" triggered my "huh?" sensor. It >> is a robust way, but is there something particularly "secure" about >> it, other than "it is less likely to break your repository" in the >> sense that is already covered by "robust". > > We know that sharing a working tree with different users is not secure > because people can have things like hooks or config options that execute > arbitrary code. Transferring stashes doesn't have that downside. Ah, I wasn't thinking about two different people transferring repositories. Using rsync may have that downside.