Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
leni536
46 days ago
|
parent
|
context
|
favorite
| on:
Breaking Git with a carriage return and cloning RC...
The question is whether recursive submodule checkout happens after some integrity/signature validation or before. The RCE can be an issue in the latter case.
johncolanduoni
45 days ago
[–]
There would also have to be a compromise of the transport (i.e. a MITM of HTTPS or SSH) to use this in most practical scenarios.
leni536
45 days ago
|
parent
[–]
It still weakens the security, otherwise why bother with integrity/signature checks if you trust the git remote?
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: