Altered Histories in Version Control System Repositories: Evidence from the Trenches
Solal Rapaport, Laurent Pautet, Samuel Tardieu, Stefano Zacchiroli
Abstract
Version Control Systems (VCS) like Git allow developers to locally rewrite recorded history, e.g., to reorder and suppress commits or specific data in them. These alterations have legitimate use cases, but become problematic when performed on public branches that have downstream users: they break push/pull workflows, challenge the integrity and reproducibility of repositories, and create opportunities for supply chain attackers to sneak into them nefarious changes. We conduct the first large-scale investigation of Git history alterations in public code repositories. We analyze 111 M (millions) repositories archived by Software Heritage, which preserves VCS histories even across alterations. We find history alterations in 1.22 M repositories, for a total of 8.7 M rewritten histories. We categorize changes by where they happen (which repositories, which branches) and what is changed in them (files or commit metadata). Conducting two targeted case studies we show that altered histories recurrently change licenses retroactively, or are used to remove "secrets" (e.g., private keys) committed by mistake. As these behaviors correspond to bad practices-in terms of project governance or security management, respectively-that software recipients might want to avoid, we introduce GITHISTORIAN, an automated tool, that developers can use to spot and describe history alterations in public Git repositories.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 982f265c-deb7-40cf-a87f-4c99e06f9892Builds on3
- Githru: Visual Analytics for Understanding Software Development History Through Git Metadata AnalysisYoungtaek Kim, Jaeyoung Kim, Hyeon Jeon, Young-Ho Kim et al.IEEE VIS 2020 · 36 citations
- Mining Pull Requests to Detect Process Anomalies in Open Source Software DevelopmentBohan Liu, He Zhang, Weigang Ma, Hongyu Kuang et al.ICSE 2024 · 2 citations
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
Related papers
- What Challenges Do Developers Face About Checked-in Secrets in Software Artifacts?Setu Kumar Basak, Lorenzo Neil, Bradley Reaves, Laurie A. WilliamsICSE 2023 · 9 citations
- On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software VulnerabilitiesSantiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin CapposUSENIX Security 2016 · 33 citations
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 130 citations
- Pushed by Accident: A Mixed-Methods Study on Strategies of Handling Secret Information in Source Code RepositoriesAlexander Krause, Jan H. Klemmer, Nicolas Huaman, Dominik Wermke et al.USENIX Security 2023
- A Multi-Month Study of Git Commit SigningAbubakar Sadiq Shittu, John Sadik, Scott RuotiCCS 2026
