A macOS menu bar app that monitors Homebrew updates and lets you upgrade packages directly from the tray.
Find a file
maxsoch e41d7ac008 fix: exec brew directly instead of interpreting a shell string
runBrew built a command string and ran it through zsh -c, so the shell
interpreted the whole line — any metacharacter in an interpolated
package name (;, $(), backticks) would have been executed. Names come
from brew itself so exploitation was unlikely, but the injection class
is now gone: Process gets an argument array via /usr/bin/env, which
resolves brew on PATH (covering the bare "brew" fallback) and execs it
with no shell in between. Also slightly faster per invocation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 21:34:28 +02:00
.claude/skills add dev tooling from /init: swiftlint, skills, gitignore; apply swiftformat 2026-07-06 21:07:17 +02:00
asset addind logo as asset 2026-06-30 17:47:46 +02:00
BrewBar fix: exec brew directly instead of interpreting a shell string 2026-07-06 21:34:28 +02:00
BrewBar.xcodeproj add unit test target with BrewParser extraction 2026-07-06 21:17:26 +02:00
BrewBarTests add unit test target with BrewParser extraction 2026-07-06 21:17:26 +02:00
.gitignore add unit test target with BrewParser extraction 2026-07-06 21:17:26 +02:00
.swiftlint.yml add dev tooling from /init: swiftlint, skills, gitignore; apply swiftformat 2026-07-06 21:07:17 +02:00
LICENSE Initial commit 2026-06-30 15:16:27 +00:00
README.md update README 2026-06-30 15:53:48 +00:00

BrewBar's logo

Brew

A macOS menu bar app that monitors Homebrew updates and lets you upgrade packages directly from the tray.