Skip to main content

How Anonymous Push Works

gitGost provides strong anonymity by stripping all identifying metadata from your commits before creating pull requests. This guide explains the technical process and what gets anonymized.
gitGost provides strong anonymity features, but not perfect anonymity. See the Threat Model for details on what is and isn’t protected.

The Push Workflow

1

Client sends packfile

When you run git push gost, your Git client packages commits into a packfile using the Smart HTTP protocol:
The packfile contains:
  • Commit objects (with your original author/committer info)
  • Tree objects (file structure)
  • Blob objects (file contents)
  • Parent commit references
2

gitGost receives and extracts

The server extracts the packfile from the Git protocol wrapper:
3

Commits are unpacked

gitGost unpacks your commits into a temporary repository:
4

Metadata is anonymized

Every commit is rewritten with anonymous author/committer signatures:
Your commit message is preserved—only identity metadata is stripped.
5

Fork is created

A fork is created under the @gitgost-anonymous account:
6

Anonymized commits are pushed

The rewritten commits are pushed to a unique branch in the fork:
7

PR is opened

A pull request is created from the fork to the original repository:

What Gets Anonymized

✅ Stripped Metadata

Your name and email are replaced in all commits.
Even if you amended commits, the committer is anonymized.
Original timestamps are replaced with the server’s current time to prevent timezone-based identification.
PRs appear from @gitgost-anonymous, not your personal account. No link between your GitHub profile and the contribution.

✅ Preserved Data

Your commit messages are preserved exactly as written and used as the PR description. Write them carefully—see commit message best practices.
The actual diff (added/removed lines) is preserved. This is necessary for the PR to be useful.
The tree structure (which files were modified) is preserved.
If you push multiple commits, the commit graph structure is preserved (parent relationships), but all metadata is anonymized.

What gitGost Does NOT Anonymize

IP Address: Your IP is visible to the gitGost server. Use Tor integration to hide your IP.
Code Style: Your coding style, variable naming, and comments can be analyzed (stylometry). Avoid unique patterns if full anonymity is critical.
Timing Patterns: Push timing can correlate with your timezone or activity patterns. Use irregular timing if avoiding correlation is important.

Commit Rewriting Details

Recursive Parent Rewriting

When you push multiple commits, gitGost recursively rewrites the entire chain:

Base Commit Detection

gitGost only rewrites new commits (your changes), not existing commits from the target repository:
This ensures:
  • Only your new commits are rewritten
  • Existing repository history remains unchanged
  • Parent references stay correct

Example: Before and After

Original Commit (Your Local Repository)

Anonymized Commit (In Fork)

Notice:
  • Author/Committer changed to @gitgost-anonymous
  • Email changed to anonymous@gitgost.local
  • Timestamp changed to server time (UTC)
  • Commit SHA changed (since metadata changed)
  • Message preserved exactly

Edge Cases and Limitations

Multiple Commits

Pushing multiple commits works correctly:
All three commits are anonymized while preserving their relationship.

Merge Commits

Merge commits are supported—both parents are rewritten:

Large Commits

Commits over 10 MB are rejected:
Solution: Split large changes into multiple smaller commits.

Binary Files

Binary files are supported, but count toward the 10 MB commit limit.

Security Considerations

Server Trust

You must trust the gitGost server not to log your IP. Use Tor if you need to eliminate this trust requirement.

Code Analysis

Advanced adversaries can analyze code style, commit patterns, and timing to potentially identify you. gitGost protects against casual identification, not targeted forensics.

GitHub Metadata

GitHub may log the IP of the @gitgost-anonymous bot account (the server’s IP), but not yours—unless you access the PR URL directly without Tor Browser.

Commit Messages

Don’t include personally identifiable information in commit messages. Avoid phrases like “I always use…” or references to your company/location.

Rate Limiting and Abuse Prevention

gitGost tracks pushes per IP address:
If you exceed 5 PRs/hour:
Use Tor integration to rotate your exit node if you need to contribute to multiple projects rapidly.

Temporary Repository Cleanup

All temporary data is deleted after the push:
gitGost does not store:
  • Your packfile
  • Original commit metadata
  • Git history
  • Any persistent state about your push

Next Steps

Tor Integration

Hide your IP address from the gitGost server

Commit Messages

Write effective commit messages for anonymous PRs

Threat Model

Understand what gitGost protects against

API Reference

Technical protocol details