Skip to content

"fetching arbitrary (maybe dangling) commits may be a security risk" #178410

@ghost

Description

This is because fetching arbitrary (maybe dangling) commits may be a security risk

Can anybody provide a pointer on why allowing dangling commits to be fetched is a security risk? I can't seem to find any details on this. Is the risk because people assume "unreachable" means "deleted"?

Metadata

Metadata

Assignees

No one assigned

    Labels

    0.kind: questionRequests for a specific question to be answered
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions