First experience with "hgsubversion" extension
Dr Rainer Woitok
rainer.woitok at gmail.com
Tue May 22 18:52:58 UTC 2018
Augie,
On Tuesday, 2018-05-22 10:38:15 -0400, you wrote:
> ...
> > What should I look out for
> > before I enable that option? Is it sufficient to just look into file
> > ".hgsub" or may the malicious stuff be hidden on the remote server?
>
> The .hgsub is where the problem could occur. As long as you’re cloning repositories you trust, you’ll be fine.
Well, this only partly answers my question. Again: can I decide by just
examining file ".hgsub" whether or not the URLs to the upstream reposit-
ories are clean? After all, simply "checking" is way more save than
just "trusting" :-/
Do I have to look for dollar signs or "$(" in the URLs?
Sincerely,
Rainer
More information about the Mercurial
mailing list