Use the array syntax for shelling out
What does this MR do and why?
Adds defense in depth to a previous fix. If validations are bypassed now the worst possible impact would be argument injection rather than a full command injection.
Screenshots or screen recordings
These are strongly recommended to assist reviewers and reduce the time to merge your change.
How to set up and validate locally
- Run
Feature.enable(:bulk_import_projects)
in your rails console - Follow this documentation to use bulk import
MR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.
-
I have evaluated the MR acceptance checklist for this MR.
Edited by Vasilii Iakliushin