-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Hooks are a security concernΒ #429
Copy link
Copy link
Closed
Labels
discussionenhancementThis issue/PR relates to a feature request.This issue/PR relates to a feature request.
Description
Executing the hooks means I trust the template source with anything reachable from my user account β hopefully everyone using templates with hooks does a review beforehand. π
I think there should be a --hooks=abort|skip|ask|trusted option that defaults to ask β many times, users won't know the difference because templates have no hooks, but it will have their backs when it counts (becoming aware they're about to execute abitrary code).
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
discussionenhancementThis issue/PR relates to a feature request.This issue/PR relates to a feature request.