Guide

An exposed .git directory gives away your source code.

Deploying with git clone or git pull straight into the web root deploys the .git folder too. If the web server serves it, your whole repository can be downloaded: every file, every commit, and every secret that was ever committed — including ones deleted since.

How to check

DotenvScan requests /.git/config in every scan. By hand:

curl -s https://example.com/.git/HEAD

A reply like ref: refs/heads/main means the directory is exposed; a 403 or 404 is what you want. If other apps are deployed in subfolders, check those paths too.

Why it’s worse than it looks

1. Block it now

# nginx (inside the server block)
location ~ /\.git {
    deny all;
}

# Apache (virtual host or .htaccess)
RedirectMatch 404 /\.git(/|$)

For Caddy, and to block .env files and backups at the same time, use the rules in the main guide.

2. Rotate what it exposed

3. Check whether it was downloaded

sudo zgrep -hE '"GET /([^ "]*/)?\.git/[^ "]* HTTP/[0-9.]+" 200 ' /var/log/nginx/access.log*

A burst of hits from one address — HEAD, config, index, then object files — means the repository was dumped. For Apache, search /var/log/apache2/access.log* or /var/log/httpd/access_log*.

4. Deploy without .git in the web root

Check your site for .git