Skip to content

My git fetch command is broken after updating from 3.1.20 to 3.1.30 #1538

Description

@gpxricky

Hi,
in gitpython version 3.1.20 I was using the following construct:

# The list is filled with information from an external source like a configuration file, current content is just an example
fetch_options = [ "--depth", "1", "tag", tag_to_fetch ] 
remote.fetch(fetch_options)

It worked fine, although I wasn't sure if I used the function properly. After updating to version 3.1.30 the following git error is raised: 'fatal: couldn't find remote ref --depth'. This is because the git cmd command changed to:

git fetch -v -- origin --depth 1 tag MY_TEST_TAG

Which is obviously wrong now. How do I need to change my fetch call in order to fetch a tag with some additional options for the command that may be read from a text file?

Many thanks and best regards,
Markus

Activity

  1. stsewd commented on Jan 13, 2023

    @stsewd
    Contributor

    Hi, similar to #1528, you were relying on a security vulnerability that allowed positional arguments to be interpreted as options (the first argument from fetch is meant to be a list of refs)

    refspec: Union[str, List[str], None] = None,

    You need to pass additional options as kwargs.

  2. gpxricky commented on Jan 13, 2023

    @gpxricky
    Author

    @stsewd Thanks for the information. So at the end, if I need to remain backwards compatible and can't change the input file, then the only solution is to change my command to

    fetch_options = [ "-v", "origin", "--depth", "1", "tag", tag_to_fetch ] 
    repo.git.fetch(fetch_options)
    

    ? I think converting the list to a dictionary is quite complicated as an option may be used with short name or long name, may be written as "--depth=1" or "--depth 1" and may contain multiple values, a single value or no value.

    Best regards,
    Markus

  3. locked and limited conversation to collaborators on Jan 14, 2023
  4. converted this issue into a discussion #1540 on Jan 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions