Replies: 1 comment 2 replies
-
After communicating with Zoltan, I agree that this is not a security issue. But it will be better if pnpm can check if the file exists before reading. The email contents are listed below: Click meHi Zoltan,I just checked it with yarn and found that yarn does not have this issue. The repo is in https://github.com/Liu233w/yarn-reading-github-event . Regards, On 10/25/22 12:50, Shumin Liu wrote:
|
Beta Was this translation helpful? Give feedback.
-
Recently I found that if environment variables like
GITHUB_EVENT_PATH
exists,pnpm test
reads theevent.json
file. Is that intended? If so, what is that used for?P.S. I created a repo to reproduce it: https://github.com/Liu233w/pnpm-reading-github-event
Beta Was this translation helpful? Give feedback.
All reactions