Protect Your .git Directory
It seems a lot of people are using Git to get their website’s into version control. That is a good thing. The truth is, however, a lot of designers don’t have too much experience with the nuances of having our code in a repository, and so we don’t always know about little security tips and tricks the pros use.
Well, here’s an important little trick I picked up from Matt Masuga’s presentation at EECI2010. If your deployed site is a working copy of your master repository, adding this simple rule to your .htaccess file will hide your .git directory from public viewing, adding a bit of extra security. This tip will actually work for any site that’s deployed on Git.
The rule is :
RedirectMatch 403 /.git.*$
This is a pretty important rule to have because it protects you from people seeing the inner workings of your server. Hope this helps someone!
Leave a comment…