Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

whitelisting `gh` args should solve it. Event opencode's primitive permission system allows that.


The ability to whitelist specific args for commands has been the source of several (countless?) sudo CVEs over the years.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: