logoalt Hacker News

ivankralast Tuesday at 8:04 AM0 repliesview on HN

Ohh, good point about git hooks as a container escape vector! I probably should add `-v $PWD/.git:$PWD/.git:ro` for that (bind-mount .git as read-only).