Your Source Code Is Showing: The Exposed .git Mistake We’ve Found for 10 Years Straight
One curl request to /.git/HEAD hands attackers your full source, every commit ever made, deleted files, and usually a working credential. A decade of research says this mistake is not aging out. Here is the exploit chain — and the three-layer fix.
