Skip to content

Commit 12b7d04

Browse files
committed
Harden bash permissions
1 parent d918754 commit 12b7d04

1 file changed

Lines changed: 12 additions & 5 deletions

File tree

.claude/settings.json

Lines changed: 12 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,17 +3,24 @@
33
"allow": [
44
"Read(//tmp/**)",
55
"Write(//tmp/**)",
6-
"Bash(*)",
6+
"Bash(bash .claude/scripts/*)",
7+
"Bash(python3 .claude/scripts/*)",
8+
"Bash(curl:*)",
9+
"Bash(date:*)",
10+
"Bash(cat:*)",
11+
"Bash(echo:*)",
12+
"Bash(wc:*)",
13+
"Bash(ls:*)",
14+
"Bash(jq:*)",
15+
"Bash(gh pr list:*)",
16+
"Bash(gh auth status:*)",
717
"WebFetch(domain:prow.ci.openshift.org)",
818
"Skill(analyze-ci-for-pull-requests)",
919
"Skill(analyze-ci-for-release)",
1020
"Skill(analyze-ci-for-release-manager)",
1121
"Skill(openshift-ci-analysis)"
1222
],
1323
"deny": [],
14-
"ask": [
15-
"Bash(sudo:*)",
16-
"Bash(git:*)"
17-
]
24+
"ask": []
1825
}
1926
}

0 commit comments

Comments
 (0)