container-hardening
container-hardening copied to clipboard
Fix Word Splitting and some minor improvments
These changes mainly address issues #2 with word splitting. The solution, using temporary files for storing the find output, is described in the Shellcheck Wiki. It isn't very clean, IMO. But posix shell obviously doesn't offer very much help here.
There is a Github Action, which runs shellcheck for static analysis, which helps preventing such issues.
And also there are some minor improvements.
Another possibility would be, to switch to bash and utilize its arrays, since the script requires ldd, which itself requires bash anyways.