What it is
When a codebase is deployed to a web server by cloning or pulling a git repository into the document root, the .git/ directory ends up publicly accessible unless the web server is explicitly configured to block it. Anyone who requests https://<domain>/.git/config and gets a 200 response can then use standard tooling to reconstruct the entire source tree, commit history, and any secrets that were ever committed and later removed.
Why it matters
Reconstructed source often contains database credentials, API keys, third-party integration tokens, and unsanitized customer data used in test fixtures. Even a "clean" current head can have secrets in history that a rotation swept from the working tree but not from the git objects.
How anyone can check it
curl -sI https://yourfirm.ca/.git/HEADA 200 response means the folder is readable from outside. It should be 403 or 404.
Remediation direction
Immediate: block .git/, .svn/, and .hg/ at the web server or CDN layer. Longer-term: deploy from a build artifact, not from a live git checkout. If any secret ever appeared in commit history, rotate that secret regardless of whether it appears in the current tree.
LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.