From a6bd481e61a6f0435b0dc8f6c3b454c39e0959e9 Mon Sep 17 00:00:00 2001 From: Dave Morin Date: Fri, 8 May 2026 00:59:09 -0700 Subject: [PATCH] fix(hooks): replace unsafe eval with declare in check-config.sh The load_env_vars function used eval to assign .env values, which executes command substitutions in backtick-containing comments. Replace eval with declare and strip inline comments before assignment. Fixes #361 --- hooks/scripts/check-config.sh | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/hooks/scripts/check-config.sh b/hooks/scripts/check-config.sh index bc57dd5..3f28b03 100755 --- a/hooks/scripts/check-config.sh +++ b/hooks/scripts/check-config.sh @@ -33,8 +33,11 @@ load_env_vars() { [[ -z "$key" ]] && continue key=$(echo "$key" | xargs) value=$(echo "$value" | xargs | sed 's/^["'\''"]//;s/["'\''"]$//') + # Strip inline comments (# preceded by whitespace) to prevent + # command substitution in backtick-containing comments + value="${value%%[[:space:]]#*}" if [[ -n "$key" && -n "$value" ]]; then - eval "ENV_${key}=\"${value}\"" + declare "ENV_${key}=${value}" fi done < "$file" fi