mirror of
https://github.com/podman-container-tools/podman.git
synced 2026-10-06 14:07:50 +00:00
sed scripts are capable of doing file I/O and executing arbitrary
commands. The `--sandbox` option prevents this by rejecting sed commands
with such capabilities; it's good practice to use this whenever the sed
script is dynamically generated (e.g. if it involves a variable
expansion).
Also fixed an error in one sed script where `.*` had been placed outside
of the quoted string (and would therefore be subject to shell globbing),
presumably due to single-quotes having been changed to double-quotes at
some point in the past.
Signed-off-by: Daniel Hast <hast.daniel@protonmail.com>
(cherry picked from commit
|
||
|---|---|---|
| .. | ||
| check_cirrus_cron.yml | ||
| ci.yml | ||
| dev-bump.yml | ||
| first_contrib_cert_generator.yml | ||
| issue-labeler.yml | ||
| issue_pr_lock.yml | ||
| labeler.yml | ||
| lima.yml | ||
| mac-pkg.yml | ||
| machine-os-pr.yml | ||
| needs-info-labeler.yaml | ||
| release-artifacts.yml | ||
| release.yml | ||
| stale.yml | ||
| update-podmanio.yml | ||
| upload-win-installer.yml | ||