Skip to content

Commit

Permalink
Add only trusted projects' bin directory to $PATH
Browse files Browse the repository at this point in the history
Assuming the binstubs for a project are in the local bin/ directory, you
can even go a step further to add the directory to shell $PATH so that
rspec can be invoked without the bin/ prefix:

    export PATH="./bin:$PATH"

However, doing so on a system that other people have write access to
(such as a shared host) is a security risk.

rbenv/rbenv#309

Put this in `zshenv` because:

http://zsh.sourceforge.net/Intro/intro_3.html

> `.zshenv' is sourced on all invocations of the shell, unless the -f
> option is set. It should contain commands to set the command search
> path.
  • Loading branch information
Dan Croak committed Jan 17, 2014
1 parent e0200f0 commit afd0c28
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions zshenv
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
# mkdir .git/safe in the root of repositories you trust
export PATH=".git/safe/../../bin:$PATH"

0 comments on commit afd0c28

Please sign in to comment.