Skip to content

Hooks are a security concernΒ #429

@jhermann

Description

@jhermann

Executing the hooks means I trust the template source with anything reachable from my user account – hopefully everyone using templates with hooks does a review beforehand. πŸ™ˆ

I think there should be a --hooks=abort|skip|ask|trusted option that defaults to ask – many times, users won't know the difference because templates have no hooks, but it will have their backs when it counts (becoming aware they're about to execute abitrary code).

Metadata

Metadata

Assignees

No one assigned

    Labels

    discussionenhancementThis issue/PR relates to a feature request.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions