Merge pull request #35483 from Packeting1/fix/secure-git-call-changelog
fix: avoid shell in changelog git calls
This commit is contained in:
commit
bc94ef1381
1 changed files with 4 additions and 4 deletions
|
|
@ -136,8 +136,8 @@ def get_app_branch(app):
|
|||
try:
|
||||
with open(os.devnull, "wb") as null_stream:
|
||||
result = subprocess.check_output(
|
||||
f"cd ../apps/{app} && git rev-parse --abbrev-ref HEAD",
|
||||
shell=True,
|
||||
["git", "-C", f"../apps/{app}", "rev-parse", "--abbrev-ref", "HEAD"],
|
||||
shell=False,
|
||||
stdin=null_stream,
|
||||
stderr=null_stream,
|
||||
)
|
||||
|
|
@ -152,8 +152,8 @@ def get_app_last_commit_ref(app):
|
|||
try:
|
||||
with open(os.devnull, "wb") as null_stream:
|
||||
result = subprocess.check_output(
|
||||
f"git -C ../apps/{app} rev-parse --short=7 HEAD",
|
||||
shell=True,
|
||||
["git", "-C", f"../apps/{app}", "rev-parse", "--short=7", "HEAD"],
|
||||
shell=False,
|
||||
stdin=null_stream,
|
||||
stderr=null_stream,
|
||||
)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue