Infra: block GIT_EXEC_PATH in host env sanitizer (#43685)

* Infra: block GIT_EXEC_PATH in host env sanitizer

* Changelog: note host env hardening
This commit is contained in:
Vincent Koc
2026-03-12 01:16:03 -04:00
committed by GitHub
parent 18f15850e6
commit 1dcef7b644
4 changed files with 60 additions and 0 deletions

View File

@@ -17,6 +17,7 @@ enum HostEnvSecurityPolicy {
"BASH_ENV",
"ENV",
"GIT_EXTERNAL_DIFF",
"GIT_EXEC_PATH",
"SHELL",
"SHELLOPTS",
"PS4",