First experience with "hgsubversion" extension

Dr Rainer Woitok rainer.woitok at gmail.com
Tue May 22 18:52:58 UTC 2018


Augie,

On Tuesday, 2018-05-22 10:38:15 -0400, you wrote:

> ...
> >                                               What should I look out for
> > before I  enable that option?   Is it sufficient  to just look into file
> > ".hgsub" or may the malicious stuff be hidden on the remote server?
> 
> The .hgsub is where the problem could occur. As long as you’re cloning repositories you trust, you’ll be fine.

Well, this only partly answers my question.  Again: can I decide by just
examining file ".hgsub" whether or not the URLs to the upstream reposit-
ories are clean?   After all,  simply "checking"  is way more  save than
just "trusting" :-/

Do I have to look for dollar signs or "$(" in the URLs?

Sincerely,
  Rainer



More information about the Mercurial mailing list