Avoid exposing Git credentials in subprocess command-line arguments
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 56/100
Research direction
Locate the code that builds Git subprocess arguments and handles credential-bearing configuration, then trace its authorization-value and repository-URL validation. Check how the child environment is assembled, including existing GIT_CONFIG_* entries and malformed counts. Done means credentials are absent from subprocess arguments while configuration preservation, validation, and scoped authorization behavior remain covered by tests.
Written by the indexing model from the issue text.
Description
Description
Cachew currently passes repository-scoped authorization credentials to Git using command-line configuration:
git -c credential.helper=<helper containing credential> ...
The credential is embedded as a literal in the helper definition, which exposes it in Git's process arguments. Command-line arguments may be visible through process inspection tools, /proc/<pid>/cmdline, diagnostic tooling, or process telemetry.
PR #321 also identified that credentials are embedded in the helper command, but addressed token refresh during long-running subprocesses. It was closed in favor of #322, which addressed token lifetime and LFS timeouts without removing credentials from process arguments.
Proposed change
Pass credential-bearing Git configuration through Git's environment-based configuration mechanism instead:
GIT_CONFIG_COUNT=<n>
GIT_CONFIG_KEY_<n>=http.<repository-scope>.extraHeader
GIT_CONFIG_VALUE_<n>=Authorization: <credential>
The implementation should:
- Preserve existing
GIT_CONFIG_COUNT,GIT_CONFIG_KEY_*, andGIT_CONFIG_VALUE_*entries. - Append the credential configuration at the next available index.
- Reject malformed, negative, or overflowing
GIT_CONFIG_COUNTvalues. - Continue validating the authorization value and repository URL scope.
- Restrict this change to credential-bearing configuration; ordinary non-sensitive Git configuration can remain in command-line arguments.
- Ensure credentials do not appear in the generated Git subprocess arguments.
Security impact
This reduces accidental credential disclosure through process listings and command-line capture. The credential remains in the child process environment, as required by Git, so access to process environments should still be restricted appropriately.
- Dominant language
- Go
- Stars
- 41
- Forks
- 14
- Avg merge
- 19h 28m
- Merged PRs (30d)
- 3
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from block/cachew
-
etag-range-followup
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
-
Difficulty 5/5 Over a week Newbie friendliness 38/100
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
Similar issues
-
bug needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
netdata/netdata#24062 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
meshery/meshery#22119 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
automation documentation
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day