This repository has been archived by the owner on Apr 14, 2021. It is now read-only.
-
-
Notifications
You must be signed in to change notification settings - Fork 2k
Don't use insecure temporary directory as home directory #7416
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The fix looks good to me, I just added a few comments but this is something we should definitely do in my opinion, specially since Debian seems to already be patching this.
fatkodima
force-pushed
the
secure-temporary-dir-as-home
branch
from
November 4, 2019 17:43
6bd9ea0
to
65cfebb
Compare
@deivid-rodriguez Updated with your suggestion of making method private. I am doubt too that anybody uses it. |
deivid-rodriguez
approved these changes
Nov 5, 2019
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good to me! I'll leave it a couple more days in case other maintainers have other insights/concerns.
Thanks for this!
@bundlerbot merge |
ghost
pushed a commit
that referenced
this pull request
Nov 7, 2019
7416: Don't use insecure temporary directory as home directory r=deivid-rodriguez a=fatkodima Closes #6501 Co-authored-by: fatkodima <[email protected]>
Build succeeded |
deivid-rodriguez
pushed a commit
that referenced
this pull request
Nov 7, 2019
hsbt
added a commit
to ruby/ruby
that referenced
this pull request
Nov 11, 2019
Features: - Add caller information to some deprecation messages to make them easier to fix [#7361](rubygems/bundler#7361) - Reconcile `bundle cache` vs `bundle package` everywhere. Now in docs, CLI help and everywhere else `bundle cache` is the preferred version and `bundle package` remains as an alias [#7389](rubygems/bundler#7389) - Display some basic `bundler` documentation together with ruby's RDoc based documentation [#7394](rubygems/bundler#7394) Bugfixes: - Fix typos deprecation message and upgrading docs [#7374](rubygems/bundler#7374) - Deprecation warnings about `taint` usage on ruby 2.7 [#7385](rubygems/bundler#7385) - Fix `--help` flag not correctly delegating to `man` when used with command aliases [#7388](rubygems/bundler#7388) - `bundle add` should cache newly added gems if an application cache exists [#7393](rubygems/bundler#7393) - Stop using an insecure folder as a "fallback home" when user home is not defined [#7416](rubygems/bundler#7416) - Fix `bundler/inline` warning about `Bundler.root` redefinition [#7417](rubygems/bundler#7417)
This pull request was closed.
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #6501