Skip to content

Add security risk on runner debug for Shell executors

Daphne Kua requested to merge dkua1-main-patch-aa77 into main

What does this MR do?

Highlight security risk on enabling runner debug mode on runners using Shell executors.

Why was this MR needed?

This came from a ticket (Zendesk ticket (internal only)) based on an incident (Zendesk ticket (internal only)) handled by @bprescott_:

image

What's the best way to test this MR?

What are the relevant issue numbers?

Merge request reports