Did you have to do anything to lockdown the .git folder?
A better approach is to put it in a subdirectory, and RTFM of Apache/nginx.
Did you have to do anything to lockdown the .git folder?