Thought I’d do a little thread on the basics of #git and some #infosec tidbits:
Very quickly - git is the most popular tool used to manage source code, and while used by services like GitHub it is a seperate thing
Some quick terms:
Repository - this is where all your code is stored, as well as a .git folder that keeps track of your history and other essential bits of info.
Commit - a snapshot in time of your files, referenced by the SHA1 hash of the state of the repository when someone chose to commit those files.
Branch - a split in the timeline, you can branch off a particular commit and continue adding to it without changing other branches.
Pull request - this is something specific to remote hosting of git repos, once someone has made a branch they can ask to merge it into the main (or another) branch.
Now for the fun tidbits:
- Commits have an author, which has details like email address and name, this can be set to anything and is not verified in any way. For example, I can create a malicious commit pretending to be someone trusted and push it to a remote, and it will be (nearly) indistinguishable from a commit by them. In order to mitigate this, sign your commits with a GPG key!
- Websites with accidentally published .git folders - these are super juicy, while the current state of the repository may not have any credentials or leaked, a .git folder contains all the history of the project, people often leak an API key once and remove it in the next commit. It’s still there in the history.
Let me know if I’ve missed any fun bits!
@kemuri this goes against the age old advice of delete the repo and start again ;p
(Very useful command)