Please report security vulnerabilities privately, not in a public issue.
Use GitHub's private vulnerability reporting: go to the Security tab and click Report a vulnerability. This opens a private advisory only the maintainers can see.
We will acknowledge your report and keep you updated as we work on a fix.
pgctl orchestrates backup tooling over ssh and a container runtime, and holds no credentials of its own — it reads object-storage credentials from the target container's environment at the moment it needs them. Reports about how those credentials are handled, how commands are constructed and quoted, or how the drill's guards could be made to pass on a bad backup are especially welcome.