aboutsummaryrefslogtreecommitdiff
path: root/devscripts/release.sh
diff options
context:
space:
mode:
authorDennis Fink2026-05-09 20:14:28 +0200
committerDennis Fink2026-05-09 20:14:28 +0200
commitcfeb338478bb67defce2fb48222a6be3cffc4263 (patch)
treeaa8fa74eef56e00bcb3b01c125460d10e1d88e80 /devscripts/release.sh
parent7f7341a84176beb4516a6801e16e2eb36557c2c8 (diff)
downloadtranscode.sh-cfeb338478bb67defce2fb48222a6be3cffc4263.tar.gz
transcode.sh-cfeb338478bb67defce2fb48222a6be3cffc4263.zip
refactor(core): remove hardcoded PATH reset
PATH='/bin:/usr/bin:/usr/local/bin' was intended as a security measure against PATH injection. For a script invoked manually in the user's own shell the benefit is marginal: if an attacker controls the user's PATH they already have larger problems. The cost is real — tools installed outside these three directories (Homebrew, Nix, ~/.local/bin) silently fail, and the documented workaround of prepending a path at invocation time does not work because the script overwrites PATH immediately on startup. Remove the PATH reset and all associated documentation. The remaining hardening measures (unalias -a, hash -r, strict set -o flags, umask) are retained.
Diffstat (limited to 'devscripts/release.sh')
0 files changed, 0 insertions, 0 deletions