This policy is giving bad advice. The <> operator is security unsafe, as it interprets filenames as if passed to the two-form open function, which means it can do code injection via crafted filenames. While reading from <STDIN> directly might not always be correct, its consequences are far milder than the damage inflicted by the diamond operator. Change-Id: I0fdf097be3b5e2a3a483f2e5d80f4fdb1f17911bchanges/31/26731/2
parent
2f1c30c0aa
commit
23dedd4b0c
Loading…
Reference in new issue