shouldiuse.io

Categories

VERDICT

Should I use Git Large File Storage?

Git LFS replaces large files like audio, video, datasets, and graphics with text pointers in Git, storing contents on a remote host. - git-lfs.com

Depends. Buy it if your team already lives in Git/GitHub and occasionally versions large files — it's free and standard. Skip it for binary-heavy workflows like game development, where metered costs pile up and Perforce is the industry norm.

Confidence

Medium. Based on ~40 public sources: official docs, CVE databases and advisories, Reddit threads, and vendor guides. No structured review ratings exist for Git LFS itself.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support evidence in sources
  • Security posture

Pricing

$0

Git LFS client (open source)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
GitHub (metered)Free quota, then $0.0875/GiB

Best for

  • Teams already on GitHub/GitLab/Bitbucket
  • Occasional large assets inside code repos
  • Datasets, graphics, audio next to code
  • Open-source projects hitting Git size limits

Not for

  • Game studios — Perforce is the AAA standard for big binaries
  • Anyone using it as a general non-code file dump
  • Solo users with a few big files — plain cloud storage is simpler
  • Teams that can't stomach per-GiB metered bills

Gotchas - check before you buy

high

GitHub bills $0.0875/GiB on new Enterprise metered accounts; bandwidth adds up fast

high

Users report hitting 'Git LFS budget exceeded' on GitHub

medium

GitHub's file-size limits still apply; LFS doesn't lift every cap

medium

Migration pain: teams replace GitHub LFS with S3/R2 proxies to cut costs

Pros and cons

Pros

  • Open source; works across GitHub, GitLab, Bitbucket, Azure DevOps
  • Keeps big files out of Git history via text pointers
  • Documented and supported by every major Git host
  • GitHub recently made free LFS storage more generous

Cons

  • Metered storage and bandwidth costs escalate quietly
  • Not the standard for game dev; Perforce preferred there
  • Recurring security vulnerabilities, including remote code execution
  • Some users advise avoiding it for large-file workflows

Sources & method

Analyzed 9/25/2026 - 13 sources - History of real vulnerabilities including a 2020 remote code execution and a 2025 academic protocol study; distros shipped 2026 patches. Keep the client updated.

official x6review x4security x2news x1
  • CVE-2020-27955, Remote code execution in Git LFS during Smart HTTP operations.
  • CVE-2021-21237, High-severity issue when Git LFS operates on malicious repos on Windows.
  • CVE-2024-53263, Git LFS vulnerability published January 2025; patch via advisory.
  • 2026 RHEL/Rocky Linux security updates, Red Hat (RHSA-2026:66364) and Rocky Linux shipped Important-severity git-lfs patches.

Key stats

  • Value for money: 3/5

    Rating

  • $0

    Starting price

  • 13

    Sources

  • Analyzed

  • Value for money: 3/5. Client is free; metered host fees surprise teams
  • Ease of use: 3/5. Works, but needs install and tracking setup
  • Feature depth: 3/5. One job: pointers plus remote file store
  • Support quality. No support evidence in sources
  • Security posture: 2/5. Multiple CVEs including RCE; 2025 protocol study
  • $0.0875/GiB Metered price (GitHub) New Enterprise accounts, metered billing since June 2024
  • Yes Free tier GitHub Free includes LFS storage/bandwidth quota
  • April 2015 First released Open-source Git extension, incubated by GitHub

Pricing

Git LFS client (open source)

$0

  • Free, open-source Git extension
  • Storage billed by your Git host, not Git LFS

GitHub (metered)

Free quota, then $0.0875/GiB

  • Free tier includes LFS storage/bandwidth
  • Enterprise accounts metered since June 2024

Security

History of real vulnerabilities including a 2020 remote code execution and a 2025 academic protocol study; distros shipped 2026 patches.

  • CVE-2020-27955Remote code execution in Git LFS during Smart HTTP operations.⁷
  • CVE-2021-21237High-severity issue when Git LFS operates on malicious repos on Windows.

Keep the client updated.

  • CVE-2024-53263Git LFS vulnerability published January 2025; patch via advisory.
  • 2026 RHEL/Rocky Linux security updatesRed Hat (RHSA-2026:66364) and Rocky Linux shipped Important-severity git-lfs patches.
Full analysis

Based on ~40 public sources: official docs, CVE databases and advisories, Reddit threads, and vendor guides. No structured review ratings exist for Git LFS itself.

Free Git extension for big files — fine for occasional assets, costly for constant binary churn; game devs should look at Perforce.

Methodology

Based on ~40 public sources: official docs, CVE databases and advisories, Reddit threads, and vendor guides. No structured review ratings exist for Git LFS itself.

Sources

  1. official
  2. official
  3. news
  4. official
  5. official
  6. official
  7. security
  8. security
  9. review
  10. review
  11. review
  12. review
  13. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.