v3.2.9 — Full CodeQL alert resolution + supply chain hardening #20
jovanSAPFIONEER
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
What's Changed
Fixed
ci.yml,codeql.yml, anddependabot-auto-merge.ymlpinned to full commit SHA; prevents supply chain attacks via mutable version tagspermissions: read-alladded to CodeQL workflow; workflows no longer carry implicit write accessexistsSync+readFileSyncTOCTOU pattern removed fromlocked-blackboard.ts; now reads directly and handlesENOENT, closing the check-then-act windowexistsSync,writeFileSyncfromsecurity.tsandstatSyncfromlocked-blackboard.tsword_count > 0ternary incheck_permission.py(guaranteed>= 3by earlier guard)passexcept blocks acrossblackboard.py,swarm_guard.py, andvalidate_token.pyRelease history
eval()from distributed code — Socket score recovery315/315 tests passing
Installation
Beta Was this translation helpful? Give feedback.
All reactions