Hacker News new | ask | show | jobs
by nopurpose 55 days ago
whitelisting `gh` args should solve it. Event opencode's primitive permission system allows that.
1 comments

The ability to whitelist specific args for commands has been the source of several (countless?) sudo CVEs over the years.