Branching and merginghard5-8 years

A developer rebases their own feature branch and pushes with `git push --force-with-lease`, expecting it to refuse if a colleague pushed to the same branch in the meantime. It doesn't refuse, and the colleague's commit is gone from the remote. What went wrong with the safety it's supposed to provide?

--force-with-lease compares against the developer's own remote-tracking ref — the branch state recorded the last time they fetched — not against whatever the remote actually holds right now. If anything refreshed that remote-tracking ref in the background after the colleague's push but before the force-push — a background git fetch, an IDE that polls periodically, a CI integration — the lease silently updates to match the colleague's new commit, and the force-push then sees "the remote matches what I last saw" and proceeds, overwriting the colleague's work anyway. The lease is a real safety check, but it's checking against a snapshot that can go stale without the developer doing anything themselves — it's a seatbelt, not a guarantee.

The lesson behind it →
More on Branching and merging