inklap

RESEARCH OF METHODS AND TOOLS FOR IMPROVING GIT LFS PROTOCOL SECURITY

Volodymyr Havryliak · Cybersecurity: Education, Science, Technique · 2025

In the current landscape of rapidly evolving DevOps and MLOps practices, the Git version control system has become the industry standard, capturing over 90% of the development market. The surge in machine learning adoption and the necessity of versioning large binary objects (ML models, datasets) have driven the widespread implementation of the Git Large File Storage (LFS) extension. However, the specific architecture of this protocol, based on separating metadata from file content, creates a new, critical attack surface that remains insufficiently explored within the context of Software Supply Chain Security. ​In light of these issues, the objective of this study is to perform a systemic analysis of architectural vulnerabilities in the Git LFS protocol and to develop a comprehensive set of practical recommendations for enhancing infrastructure security. To achieve this, threat modeling methods and experimental testing in a controlled environment were applied, specifically involving data migration between GitLab and GitHub. Additionally, the Batch API specification and hybrid authentication mechanisms were analyzed in detail. ​The study experimentally confirmed that using a hybrid

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً