threads / discuss / 45147

enhance git-add to avoid password being staged or committed?

Subject: enhance git-add to avoid password being staged or committed?

## tl;dr

2 messages between Feb 15, 2017 and Feb 15, 2017.

replies: 1people: 2as markdown or json

ryenus· Feb 15, 2017, 14:36 UTC · lore

This can be an optional feature, once enabled, git-add would check the hunk(s) to stage for sensitive information, such as passwords, secret tokens, then ask the user for confirmation.

The implementation for secret detection could be regexp pattern(s), and/or (trusted?) commands

Alternative solutions might be hooks during commit, push or recieve, but it should be the best to do this in the first place during git-add.

The context of this is the following HN discussion about passwords on
GitHub: https://news.ycombinator.com/item?id=13650818
Jeff King· Feb 15, 2017, 21:26 UTC · re: ryenus · lore

Re: enhance git-add to avoid password being staged or committed?

On Wed, Feb 15, 2017 at 10:36:32PM +0800, ryenus wrote:
Show 9 quoted lines
> This can be an optional feature, once enabled, git-add would check the
> hunk(s) to stage for sensitive information, such as passwords, secret
> tokens, then ask the user for confirmation.
> 
> The implementation for secret detection could be regexp pattern(s),
> and/or (trusted?) commands
> 
> Alternative solutions might be hooks during commit, push or recieve,
> but it should be the best to do this in the first place during git-add.

There are already hooks for commit and receive to catch things locally and at publishing time, respectively. It's possible that an "add" hook could be more useful, but I'd be a lot more convinced if people were actively doing secret-detection in their commit hooks and had some specific complaint that could be addressed by having an "add" hook.

-Peff

← back to recent threads