You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What
eval runs a piece of text as a command, and trap sets a command to run later when the shell receives a signal. When the rm safety check scans commands that contain $ and assign variables, it now looks inside the text given to trap as well as to eval. It also strips any opening quotes, so an rm wrapped in a quoted eval or trap string is checked too.
Why
A risky removal tucked inside a quoted eval or trap could previously pass the check unexamined. It is now caught like any other rm.