go-gitsafe

go-gitsafe

Guards that do not rely on remembering.

Reference GitHub

What is go-gitsafe?

A secret that CAN reach an output stream eventually does, and being careful is not a control. go-gitsafe is the set of refusals that replace the care: a global pre-push hook that rejects any push whose remote URL carries a credential and any write to the branch pull requests land on, a credential helper that serves a token to git over a pipe and never to a command line, a scope checker that reads a token's powers without printing it, and a push wrapper that never reads the token at all.

Packages

1 module(s) in this organisation.

S
gitsafe
The hook, the credential helper, the scope checker and the push wrapper — one module, no cgo.