spiegel_podman/.github
Daniel Hast d97883bcc5
ci: use --sandbox for dynamically generated sed scripts
sed scripts are capable of doing file I/O and executing arbitrary
commands. The `--sandbox` option prevents this by rejecting sed commands
with such capabilities; it's good practice to use this whenever the sed
script is dynamically generated (e.g. if it involves a variable
expansion).

Also fixed an error in one sed script where `.*` had been placed outside
of the quoted string (and would therefore be subject to shell globbing),
presumably due to single-quotes having been changed to double-quotes at
some point in the past.

Signed-off-by: Daniel Hast <hast.daniel@protonmail.com>
(cherry picked from commit 3f4af378f4)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-06-08 15:22:46 +02:00
..
actions/check_cirrus_cron GHA: Fix bad job-names & links in monitoring emails 2023-06-07 15:22:17 -04:00
ISSUE_TEMPLATE Enhance issue reporting template 2025-03-31 09:41:01 -05:00
workflows ci: use --sandbox for dynamically generated sed scripts 2026-06-08 15:22:46 +02:00
filters.yaml ci.yml: add windows jobs 2026-06-04 20:04:26 +02:00
issue-labeler.yml github: label issues based on os fix regex 2022-01-27 21:24:34 +01:00
ISSUE_TEMPLATE.md Update the issue templates 2022-11-30 14:06:29 -05:00
labeler.yml .github/labeler: add governance label automatically 2025-04-08 19:40:35 +02:00
PULL_REQUEST_TEMPLATE.md cirrus.yml: automatic skips based on source 2024-07-04 11:32:36 +02:00
renovate.json5 Detect and fix typos using codespell 2024-09-05 13:56:39 -04:00