Hacker News new | ask | show | jobs
by kibwen 455 days ago
It's even more insidious than that! Even navigating to a directory in a checkout of a hostile git repo can run arbitrary code if your shell displays git info (what branch you're on, etc).