Documentation Index
Fetch the complete documentation index at: https://tally.wharflab.com/llms.txt
Use this file to discover all available pages before exploring further.
powershell/PSAvoidUsingInvokeExpression is a PSScriptAnalyzer diagnostic emitted by tally for PowerShell snippets embedded in Dockerfiles.
| Property | Value |
|---|---|
| Severity | Warning |
| Category | PSScriptAnalyzer |
| Auto-fix | No |
Description
Care must be taken when using theInvoke-Expression command. The Invoke-Expression executes the
specified string and returns the results.
Code injection into your application or script can occur if the expression passed as a string
includes any data provided from the user.
How
Remove the use ofInvoke-Expression.