Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Avoid exposing Git credentials in subprocess command-line arguments

Đang mở
#402 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
56/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
go
Lĩnh vực
security

Hướng nghiên cứu

Tìm đoạn mã xây dựng các đối số cho tiến trình con của Git và xử lý cấu hình chứa thông tin xác thực, sau đó lần theo việc xác thực các giá trị ủy quyền và URL kho lưu trữ của nó. Kiểm tra cách môi trường của tiến trình con được thiết lập, bao gồm các mục GIT_CONFIG_* hiện có và các số lượng bị sai định dạng. Công việc được xem là hoàn tất khi thông tin xác thực không xuất hiện trong các đối số của tiến trình con, đồng thời việc bảo toàn cấu hình, xác thực và hành vi ủy quyền theo phạm vi vẫn được các bài kiểm thử bao phủ.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Description

Cachew currently passes repository-scoped authorization credentials to Git using command-line configuration:

git -c credential.helper=<helper containing credential> ...

The credential is embedded as a literal in the helper definition, which exposes it in Git's process arguments. Command-line arguments may be visible through process inspection tools, /proc/<pid>/cmdline, diagnostic tooling, or process telemetry.

PR #321 also identified that credentials are embedded in the helper command, but addressed token refresh during long-running subprocesses. It was closed in favor of #322, which addressed token lifetime and LFS timeouts without removing credentials from process arguments.

Proposed change

Pass credential-bearing Git configuration through Git's environment-based configuration mechanism instead:

GIT_CONFIG_COUNT=<n>
GIT_CONFIG_KEY_<n>=http.<repository-scope>.extraHeader
GIT_CONFIG_VALUE_<n>=Authorization: <credential>

The implementation should:

  • Preserve existing GIT_CONFIG_COUNT, GIT_CONFIG_KEY_*, and GIT_CONFIG_VALUE_* entries.
  • Append the credential configuration at the next available index.
  • Reject malformed, negative, or overflowing GIT_CONFIG_COUNT values.
  • Continue validating the authorization value and repository URL scope.
  • Restrict this change to credential-bearing configuration; ordinary non-sensitive Git configuration can remain in command-line arguments.
  • Ensure credentials do not appear in the generated Git subprocess arguments.
Security impact

This reduces accidental credential disclosure through process listings and command-line capture. The credential remains in the child process environment, as required by Git, so access to process environments should still be restricted appropriately.

Ngôn ngữ chính
Go
Star
41
Fork
14
Merge trung bình
19 giờ 28 phút
Pull request đã merge (30 ngày)
3

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của block/cachew

Tất cả issue của block/cachew

Issue tương tự

Thêm issue về Go

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.