Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
IgorPartola
on Dec 18, 2014
|
parent
|
context
|
favorite
| on:
Git client vulnerability announced
brew update will use `git clone`, so yeah...
brandonbloom
on Dec 18, 2014
|
next
[–]
Presumably you already trust homebrew to run arbitrary code on your machine.
markcerqueira
on Dec 18, 2014
|
prev
|
next
[–]
You better walk over to the Homebrew office and get the update on a USB stick then, Mr. Safety!
necubi
on Dec 18, 2014
|
prev
|
next
[–]
If you read the blog post, GitHub has checked all their repos for for this exploit and is blocking it on pushes; cloning from GitHub
should
be safe.
IgorPartola
on Dec 19, 2014
|
parent
|
next
[–]
The blocking pushes is what I was concerned with, along with brew searching pull requests.
apetresc
on Dec 18, 2014
|
prev
[–]
I'm fairly confident Homebrew isn't exploiting this
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: