Branch: refs/heads/fix_escaping_in_rakefile_testing
Home: https://github.com/openSUSE/open-build-service
Commit: bf1b07775098e9b094ff52c2da4a21d7e2a130c1
https://github.com/openSUSE/open-build-service/commit/bf1b07775098e9b094ff52...
Author: Björn Geuken
Date: 2018-05-29 (Tue, 29 May 2018)
Changed paths:
M Rakefile
Log Message:
-----------
[dist] Use multiple arguments in our Rakefile
This prevents us from interpolating user input.
Our rakefile is passing certain environment variables to the
docker-compose command. Since we were not escaping these parameters
it was possible to manipulate or break the command, eg. by having
a ' character in a commit message.
Found due to a failure in travis:
rake docker:test:lint
...
sh: 7: Syntax error: Unterminated quoted string
**NOTE:** This service been marked for deprecation: https://developer.github.com/changes/2018-04-25-github-services-deprecation/
Functionality will be removed from GitHub.com on January 31st, 2019.