Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Deploy is a simple `git pull`

Did you have to do anything to lockdown the .git folder?



Why do you think the file system is accessible at all? Due to possible errors in the script?


It is common for noobs to put index.cgi (or whatever) in the root of the git repo, and to point Apache at that by cutting and pasting a hello world example from google.

A better approach is to put it in a subdirectory, and RTFM of Apache/nginx.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: