You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please exclude support for environment variables in the templates (the .Env.* insertions according to the documentation). This can expose a lot of unintentional information (just run set in your shell to see what is available).
Preferred behaviour:
Change default value of --no-sys-env to true (or rename option).
Remove all support for system environments and only accept definitions from --env, --json or --load.
Simple work around is to add --no-sys-env parameter.
The text was updated successfully, but these errors were encountered:
FlipSky
changed the title
Do not use environment variables - security issue
Do not use environment variables by default - security issue
Nov 28, 2020
Please exclude support for environment variables in the templates (the
.Env.*
insertions according to the documentation). This can expose a lot of unintentional information (just runset
in your shell to see what is available).Preferred behaviour:
--no-sys-env
totrue
(or rename option).--env
,--json
or--load
.Simple work around is to add
--no-sys-env
parameter.The text was updated successfully, but these errors were encountered: