問題文
Which set of practices does the documentation recommend for writing hook scripts safely?
選択肢
- Write hooks in the shell of the developer's choice and rely on the platform to translate them.
- Disable timeouts so long checks can complete, and cache nothing so results are always fresh.
- Always validate and sanitize the input the hook processes, and use proper shell escaping when constructing commands to prevent command injection.
- Run hooks with elevated privileges so they can enforce policy, and log all inputs including tokens for auditing.