14
How to audit a shell-completion script?
(lemmy.ml)
The mojo, cpan and pip bash scripts don't fail my test of "skimming over the source and looking for dangerous external commands like curl or rm
" (good syntax highlighting is helpful here). They look like typical completion scripts. However, if your Linux distribution has a pip completion script in their repos, prefer that one.
Thanks. At least I've got a few clues to look for when auditing such code.
Auditing is nothing more than reading the code. Give it a read and make sure you understand everything it’s doing.
This is a great lesson on trust as well. I can tell you I did an audit and it all looks good but does that really have any value?
Agree w/ you re trust.
A general programming discussion community.