Skip to content

Comments

Security hardening#3

Merged
mheadd merged 1 commit intomainfrom
hardening-action
Dec 2, 2025
Merged

Security hardening#3
mheadd merged 1 commit intomainfrom
hardening-action

Conversation

@mheadd
Copy link
Contributor

@mheadd mheadd commented Dec 2, 2025

  • Add sanitize-diff input and wire through index → renderer
  • Restrict template file paths to repo root; reject traversal/absolute
  • Remove dry-run body preview logging to reduce exposure
  • Update README with security notes and permissions guidance

- Add sanitize-diff input and wire through index → renderer
- Restrict template file paths to repo root; reject traversal/absolute
- Remove dry-run body preview logging to reduce exposure
- Update README with security notes and permissions guidance
@mheadd mheadd merged commit ae69bbb into main Dec 2, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant