Skip to content

Prevent TrojanSourceInjection in gitk #70

@vn971

Description

@vn971

Hi! Could gitk (and if possible git gui) please implement protections against "trojan source injection"?

In short, as a developer that reviews other people's code (and potentially decides on merging),
I would like to see the code and diffs in a safe way that protects me from said attack.
E.g. if somebody submits malicious merge request to my repo, I want to see that from gitk / git gui.

Example of such source code can be seen here:
https://blog.rust-lang.org/2021/11/01/cve-2021-42574.html

Missing this type of injection could be catastrophic

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions