1. 7
  1.  

  2. 3

    The only good solution is to remove the “feature” of evaluating code in environment variables.

    1. [Comment removed by author]

      1. 2

        I say let them break. With hindsight, it seems like a silly non-standard legacy feature. We now live in a world of setuid and networking and I don’t see any use case for responsible use in such an environment.

        1. 2

          Really? I’ve been coding in Bourne shells for decades now (oof) and had never heard of this “feature.”