Git-landmine – Create local malicious Git repo
github.com
github.com
I don't see any actual exploit here.
There is an issue around embedded bare repos in archives, however, that is not the given exploit in the linked repo at all.
That said, I also don't actually put "." in my path, though this is mainly so I can avoid heisenbugs rather than a security concern...
SL(6) Games Manual SL(6)
NAME
sl - display animations aimed to correct users who acci-
dentally enter sl instead of ls.It's inconvenient that you don't get e.g. pre-commit hooks installed when you clone a repo, but it also makes total sense from a security perspective.
I don't understand folks who want their tools to fight them.
The thing about teams is that they’re made up of people with different needs, and the tooling works to benefit the entire team not just one specific opinionated individual.
Formatting and linting is frequently done in precommit hooks. This avoids a much longer feedback loop of CI failures for trivial tasks that add at most a couple of seconds to a commit (usually less).
If you don’t like it, you can simply eject out of it using the no-verify flag instead of complaining about having to fight tooling that benefits everyone else.
The problem with hooks is that inevitably the smartass who sets them up thinks they're clever and makes the hooks so elaborate that they are borderline inaccessible outside of the hook themselves. Just put the linter in the lint build rule. I'm an adult, I can run builds and tests and lints myself. I'm fully capable of ensuring my code is of sufficient quality prior to CI.
If you're not capable of that, then certainly do what you need to. Having others help you is great as well. It's always a good to make things easy to get right out of the box.
But don't make your problem my problem.
Been coding professionally for a few decades now and I completely understand and validate this. I also do not understand the drive to want tools that fight them. Our CI is so slow doing IMO unnecessary checks. Code is prettified to look ugly and hard to read because others were too lazy to align text manually and just gave up on nice looking code.
All in the name of “making it easier for the less experienced.” To which I cringe because instead of investing in education and team quality standards we invest in tools to enforce a lowest common denominator in a failed attempt to pretend it increases quality when it just gets in everyones’ way.
I’d rather educate and engender personal quality, aesthetics, and pride in their own work. And if others don’t feel that quality matters then they are not a good fit for my team.
sudo: cd: command not found
sudo: "cd" is a shell built-in command, it cannot be run directly.
sudo: the -s option may be used to run a privileged shell.
sudo: the -D option may be used to run a command in a specific directory.Lots of editors will also query git repo information for displaying information to the user, and may do this completely automatically.
If you "git clone" the repo, git will not clone hooks from my understanding, so the primary issue is unpacking a tarball with a git repo inside of it and then trying to do something with the repo.
I made a little test repo for this a while back https://github.com/abathur/LittleGaryGitles :)
git clone https://git.0x90.space/vmann/pwnd && cd pwnd/whoot && git status
it is a bit crazy this is not disabled by default yet.> not disabled by default yet
You're saying there's a way to "disable" this behavior?