Bugzilla – Bug 1143661
AUDIT-FIND: obs-service-bundle_gems: calls cpio instead of bsdtar
Last modified: 2020-11-25 08:56:31 UTC
should probably use bsdtar instead of cpio
not sure that bsdtar is that much better, but passing --no-absolute-filenames to cpio would be a good idea. A generic solution of sandboxing the operation no matter which tool is used would be my preferred solution