fix(security): Avoid shelling curl command

This commit is contained in:
sickn33
2026-04-07 20:16:53 +02:00
parent ba6a92afd3
commit 0a7a869ad4

View File

@@ -28,7 +28,11 @@ function runCommand(cmd) {
}
function fetchText(url) {
return runCommand(`curl -fsSL --max-time 30 ${JSON.stringify(url)}`);
return cp.execFileSync("curl", ["-fsSL", "--max-time", "30", url], {
encoding: "utf8",
maxBuffer: 32 * 1024 * 1024,
cwd: ROOT,
});
}
function parseOptionalYaml(relPath) {