Skip to content

Conversation

@guedou
Copy link

@guedou guedou commented Oct 14, 2024

Context

Cloning a repository with git clone --mirror may retrieve more git objects, and lead to more secrets being detected.

What has been done

By default ggshield now used --mirror. A new command line option could be used to disable this feature.

Validation

Clone https://github.com/nightwatchcybersecurity/gb_testrepo_delete?tab=readme-ov-filewith and without the new option.

@agateau-gg agateau-gg self-requested a review October 22, 2024 16:58
@codecov
Copy link

codecov bot commented Oct 28, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 91.90%. Comparing base (537dbb8) to head (b0a6765).
Report is 4 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #981   +/-   ##
=======================================
  Coverage   91.90%   91.90%           
=======================================
  Files         181      181           
  Lines        7593     7593           
=======================================
  Hits         6978     6978           
  Misses        615      615           
Flag Coverage Δ
unittests 91.90% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Copy link
Collaborator

@agateau-gg agateau-gg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi, sorry for the late review. This looks good! It's always nice to be able to spot more secrets!

I think we don't need the --no-mirror option. I'd rather not have it for now and add it only if we find a use-case for it: That's one less code path to test.

@guedou guedou force-pushed the gvaladon/git-clone-mirror branch from adb45e1 to b0a6765 Compare October 30, 2024 08:57
Copy link
Collaborator

@agateau-gg agateau-gg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, thanks!

@agateau-gg agateau-gg enabled auto-merge October 30, 2024 09:21
@agateau-gg agateau-gg merged commit 2265aa5 into GitGuardian:main Oct 30, 2024
33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants