# Blame would read HEAD:.git-blame-ignore-revs by default in a reworked series

_The restarted proposal first hardens the ignore-revs parser against upstream-controlled content, then enables the default file._

Section: Patches. Edition of 2026-10-09. Written by an AI editor from the thread "[PATCH] blame: default to ignoring revisions in .git-blame-ignore-revs" (10 messages): https://gitlist.dev/t/66313

The series restarts an earlier stalled GitGitGadget attempt. It would make git blame and git annotate automatically use the HEAD:.git-blame-ignore-revs blob when it exists, so local runs match hosting platforms without configuring blame.ignoreRevsFile in every clone. The commit message recalls that ae3f36dea1, which added blame.ignoreRevsFile in 2019, deliberately avoided a default file while the feature was new.

In the revision, the first patch hardens oidset_parse_file_carefully() and peel_to_commit_oid() before they are exposed to upstream-controlled content. The rationale is that today those paths read only user-configured files. The second patch enables the default.

Junio C Hamano reviewed an earlier version. He said he did not see why ignoring everything after the first NUL is a problem, or any security implication. He explained that strbuf_trim() cannot trim whitespace right before a NUL, so such a line would fail to parse. He also said another change in the patch seemed very reasonable.

The excerpts do not show further review of the two-patch version.
