{{ message }}
Commit 3af0c25
Block unsafe checkout-index and tag file options
GHSA-3f7w-8rr8-f37f reports that caller-controlled options forwarded by
IndexFile.checkout() and TagReference.create() can make Git write to or read
from arbitrary filesystem paths.
Add regression coverage proving the unsafe options are rejected by default while
preserving the explicit allow_unsafe_options escape hatch. Reuse GitPython's
existing option candidate normalization and unsafe-option guard at both public
API boundaries.
Git baseline: a23bace963d508bd96983cc637131392d3face18.
Documentation/git-checkout-index.adoc defines --prefix as prepending an output
path, and Documentation/git-tag.adoc defines -F/--file as reading a tag message
from a file.
Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>1 parent 07e8055 commit 3af0c25
4 files changed
Lines changed: 48 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
| |||
42 | 43 | | |
43 | 44 | | |
44 | 45 | | |
| 46 | + | |
| 47 | + | |
45 | 48 | | |
46 | 49 | | |
47 | 50 | | |
| |||
92 | 95 | | |
93 | 96 | | |
94 | 97 | | |
| 98 | + | |
95 | 99 | | |
96 | 100 | | |
97 | 101 | | |
| |||
121 | 125 | | |
122 | 126 | | |
123 | 127 | | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
124 | 131 | | |
125 | 132 | | |
126 | 133 | | |
127 | 134 | | |
128 | 135 | | |
129 | 136 | | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
130 | 143 | | |
131 | 144 | | |
132 | 145 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| 34 | + | |
34 | 35 | | |
35 | 36 | | |
36 | 37 | | |
| |||
202 | 203 | | |
203 | 204 | | |
204 | 205 | | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
205 | 215 | | |
206 | 216 | | |
207 | 217 | | |
| |||

0 commit comments