From cfeb338478bb67defce2fb48222a6be3cffc4263 Mon Sep 17 00:00:00 2001 From: Dennis Fink Date: Sat, 9 May 2026 20:14:28 +0200 Subject: refactor(core): remove hardcoded PATH reset PATH='/bin:/usr/bin:/usr/local/bin' was intended as a security measure against PATH injection. For a script invoked manually in the user's own shell the benefit is marginal: if an attacker controls the user's PATH they already have larger problems. The cost is real — tools installed outside these three directories (Homebrew, Nix, ~/.local/bin) silently fail, and the documented workaround of prepending a path at invocation time does not work because the script overwrites PATH immediately on startup. Remove the PATH reset and all associated documentation. The remaining hardening measures (unalias -a, hash -r, strict set -o flags, umask) are retained. --- README.md | 8 -------- 1 file changed, 8 deletions(-) (limited to 'README.md') diff --git a/README.md b/README.md index a01de23..09ee1d3 100644 --- a/README.md +++ b/README.md @@ -59,14 +59,6 @@ install -Dm644 transcode.sh.bash-completion \ ~/.local/share/bash-completion/completions/transcode.sh ``` -> **PATH note:** the script resets `PATH` to `/bin:/usr/bin:/usr/local/bin` -> for security. If your `ffmpeg` lives elsewhere (e.g. Homebrew on macOS, -> Nix), prepend its directory: -> -> ```sh -> PATH="/opt/homebrew/bin:$PATH" transcode.sh input.mp4 -> ``` - ## Configuration ### Presets -- cgit v1.3.1