Skip to content

www-apps:gitlabhq installs some world writable files

The www-apps:gitlabhq-9.4.1 portage build log lists some world writable files:

 * QA Security Notice: world writable file(s):
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/Rakefile
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/LICENSE
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/spec/spec_helper.rb
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/README.rdoc
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/Gemfile
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/lib/attr_optional.rb
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/.gitignore
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/VERSION
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/.travis.yml
 *   /opt/gitlabhq-9.4/vendor/bundle/ruby/2.3.0/gems/attr_required-1.0.0/.rspec
 * This may or may not be a security problem, most of the time it is one.
 * Please double check that gitlabhq-9.4.1 really needs a world writeable bit and file bugs accordingly.
 *