github / github/platform-samples

block_file_extensions.sh can be circumvented with fork + PR

Open
#165 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
2.2k
Forks
1.9k
Avg merge
7d 19h
Merged PRs (30d)
1

Description

The `block_file_extensions.sh` pre-receive-hook can be circumvented by:

1. Fork the repository
2. Add a file with the blocked exension
3. Submit a pull request
4. Merge pull request

We've done a little research and suspect that this is due to the:
```
excludeExisting="--not --all"
```

I guess we could mitigate, e.g. by adding `block_self_merge_prs.sh`, but this could still be circumvented if 2 users with write privileges colluded.

Any thoughts?

Contributor guide

Open the contributing guide

Research direction

Start by reviewing block_file_extensions.sh, especially the excludeExisting="--not --all" behavior, and trace how forked pull requests are evaluated. The issue does not name a test or a concrete fix; done would require an agreed mitigation that prevents the reported bypass while addressing the stated collusion concern.

Written by the indexing model from the issue text.

Assessment

Tech stack
shell
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.