logoalt Hacker News

emmelaichlast Sunday at 11:36 PM1 replyview on HN

Surprised that people allow force-push on git. If it needs to be done, it should only be done after consultation and disabled after.


Replies

throw14082020last Monday at 12:13 AM

It was on development branches. The threat actor was trying to delete development work.

Their main branch was already protected. I don't think it makes sense to protect every single branch in a repo? Since not all devs will have the ability to turn this off