An attacker has access to your git??? You’re fucked. Give up.
Every git repository hosting platform - GitHub, GitLab, Bitbucket, Codeberg - necessarily gives end users control over filenames.
"User-controlled strings as parameters" is not "access to your git" but it is still an attack vector.
Every git repository hosting platform - GitHub, GitLab, Bitbucket, Codeberg - necessarily gives end users control over filenames.
"User-controlled strings as parameters" is not "access to your git" but it is still an attack vector.