Hacker News new | ask | show | jobs
by nickelpro 14 days ago
They aren't. This is a Windows quirk. Most IDE extensions which interface with git (or any other CLI program) from the CWD are "vulnerable" to the same attack.

This is why the upstream didn't take it seriously, this has been known for literal decades.