Apply a secure temporary workspace pattern using `mktemp -d`, quoted paths, and `trap` cleanup.
Shared runner A report export needs scratch space for a CSV, a checksum, and a compressed archive. The runner is shared by several CI jobs. The risk is not just clutter. Predictable temp paths create race and symlink hazards. Secure temp workflow mktemp -d -> quoted workspace -> trap ... EXIT Create a private workspace, write everything inside it, and register cleanup immediately after creation. /tmp/file.$$ predictable name, manual cleanup One workspace, one cleanup path, fewer race conditions. Temporary resources deserve lifecycle management: create, own, and release. 01 Create 02 Use 03 Cleanup Race-safe name You need a place to…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in