3/3 it handle both the cases:
- simple commands go straight to argv, no shell involved
- pipes and redirections get auto quoted shell lines
also includes an audit scanner for legacy code
zero deps. check it out
https://t.co/lF0mlqU1j5
thread for why it exists:
1/3 shell injection has been in the OWASP top 10 for over a decade
every Python dev has hit it: pass user input to a shell command via f-string, watch it break.
thread for why it exists:
1/3 shell injection has been in the OWASP top 10 for over a decade
every Python dev has hit it: pass user input to a shell command via f-string, watch it break.