Skip to content

Security issue: Library-created, world-readable config file may contain secrets#197

Open
iskunk wants to merge 2 commits intoblackducksoftware:masterfrom
iskunk:new-2
Open

Security issue: Library-created, world-readable config file may contain secrets#197
iskunk wants to merge 2 commits intoblackducksoftware:masterfrom
iskunk:new-2

Conversation

@iskunk
Copy link
Contributor

@iskunk iskunk commented Sep 29, 2021

Currently, the HubInstance API writes a world-readable config file that can contain an access token, by default.

These two commits cause the file to be written with mode 600, and disables writing of the file by default.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant