Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Container serves the .git directory #42

Open
languitar opened this issue Jul 2, 2020 · 1 comment
Open

Container serves the .git directory #42

languitar opened this issue Jul 2, 2020 · 1 comment

Comments

@languitar
Copy link

In the current configuration, the created container serves the .git directory of tt-rss. This is probably not a real issue for an open source project with no private commits, but I just got an automated notification from "Deutsche Gesellschaft für Cybersicherheit", who scanned the web for potentially vulnerable servers (https://www.heise.de/ct/artikel/Massive-Sicherheitsprobleme-durch-offene-Git-Repositorys-4795181.html, German only).

@x86dev
Copy link
Owner

x86dev commented Sep 25, 2022

Yeah, I've read the article as well -- we might want to further protect that directory and/or move it further down, so that the web server only serves a copy of of the (needed) content.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants