Config Management Camp 2023 Ghent

Puppet-lint check for vulnerable exec strings
2023-02-07, 15:15–15:40, B.2.015

Puppet code that uses exec resources that execute interpolated string commands are often vulnerable to shell execution. This new lint check identifies many of these. This talk runs through the check and how it works, how to run the check and how to integrate it into your own CI testing. It will talk about future Forge integrations. And it will go through the process of writing a puppet-lint plugin to encourage others to write more.

Software engineer at Puppet.