subprocess module call
Medium
- Category
- Dangerous Code Execution
- Content
result["current_commit"] = current.stdout.strip()[:8] # 获取远程最新 commit(不拉取) subprocess.run( ["git", "fetch", "--dry-run"], cwd=str(privileged_dir), capture_output=True,- Confidence
- 89% confidence
- Finding
- subprocess.run( ["git", "fetch", "--dry-run"], cwd=str(privileged_dir), capture_output=True, text=True, timeout=30 )
