New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hide sensitive tokens from install/test/post. #2524

Merged
merged 1 commit into from Apr 23, 2017

Conversation

Projects
None yet
2 participants
@MikeMcQuaid
Copy link
Member

MikeMcQuaid commented Apr 21, 2017

Hide these tokens to avoid malicious subprocesses e.g. sending them over the network. Also, support using these tokens with environment filtering and clear HOMEBREW_PATH from subprocesses to stop them sniffing it. Finally, use HOMEBREW_PATH to detect Homebrew’s user’s PATH for e.g. brew doctor etc.

Requires the changes from #2476. Will be rebased to remove those changes when it is merged (before this PR is merged).

@MikeMcQuaid MikeMcQuaid force-pushed the MikeMcQuaid:more-env-filtering-fixes branch 3 times, most recently from b0febb5 to e4161af Apr 22, 2017

Hide sensitive tokens from install/test/post.
Hide these tokens to avoid malicious subprocesses e.g. sending them
over the network. Also, support using these tokens with environment
filtering and clear `HOMEBREW_PATH` from subprocesses to stop them
sniffing it. Finally, use `HOMEBREW_PATH` to detect Homebrew’s user’s
PATH for e.g. `brew doctor` etc.

@MikeMcQuaid MikeMcQuaid force-pushed the MikeMcQuaid:more-env-filtering-fixes branch from e4161af to d02b4f3 Apr 22, 2017

@MikeMcQuaid MikeMcQuaid merged commit 11acada into Homebrew:master Apr 23, 2017

2 of 3 checks passed

codecov/patch 51.85% of diff hit (target 63.97%)
Details
codecov/project 64.23% (+0.25%) compared to 044bd97
Details
continuous-integration/travis-ci/pr The Travis CI build passed
Details

@MikeMcQuaid MikeMcQuaid deleted the MikeMcQuaid:more-env-filtering-fixes branch Apr 23, 2017

@Homebrew Homebrew locked and limited conversation to collaborators May 3, 2018

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.