Properly escape shell arguments in pytry-many#14
Open
astoeckel wants to merge 1 commit intotcstewar:masterfrom
Open
Properly escape shell arguments in pytry-many#14astoeckel wants to merge 1 commit intotcstewar:masterfrom
astoeckel wants to merge 1 commit intotcstewar:masterfrom
Conversation
When using os.system (or really, just any kind of shell scripting), it is of utmost importance to properly escape individual arguments. For example pytry echo 'Hello World' must be substituted to echo 'Hello World' and not echo Hello World This commit fixes this problem by properly escaping individual arguments. Note that this also prevents accidental execution of commands, such as pytry echo '`rm *`'
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When using os.system (or really, just any kind of shell scripting), it is of utmost importance to properly escape individual arguments. For example
must be substituted to
and not
This commit fixes this problem by properly escaping individual arguments. Note that this also prevents accidental execution of commands, such as