fix: add security guardrails and cleanup lint warnings - #96
Open
Misaka477 wants to merge 1 commit into
Open
Conversation
This was referenced Jul 17, 2026
Collaborator
|
先说认可的部分:#88/#89/#90 三个安全 issue 都是真问题,jsGrep 的 ReDoS 兜底和「先探测再编译」的写法也对。但这个 PR 需要的返工比较多,按优先级列出:
ReDoS 防护可以保留,建议给「pattern skipped」的返回文案带上原 pattern 方便改写,并补两条启发式的边界用例。流程上:测试矩阵没跑是首次贡献者 workflow 需要我们批准,修完 push 后我们来点。三个 PR 之间有文件重叠,这个建议排在 #98/#97 之后进。改完 @ 我们。 |
… and cleanup lint warnings
Misaka477
force-pushed
the
fix/security-shell-path-traversal-redos
branch
from
July 27, 2026 16:26
bc07d01 to
36faec7
Compare
Author
|
@ZouR-Ma 已按反馈完成并 force-push:
PR body 也已同步更新。麻烦批准首次贡献者 workflow 跑三平台矩阵。 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Aligns command safety with the existing policy/inspection and approval flow, fixes workspace containment comparison, and adds ReDoS fallback guards.
Changes
ToolPolicy; nativeBashnow exposes the command throughinspect(). Dangerous commands require explicit confirmation even in auto mode or with a tool-level allow override;bashExecuteno longer hard-blocks commands.resolveWorkspacePathlogic into@step-cli/utils/path. Native tools retain their existing support for absolute paths outside the workspace;resolveInWorkspacenow uses apath.relativecontainment check to reject prefix siblings such as/repo-evil, including case-insensitive Windows comparison.Verification
pnpm check✅main.Closes #88, Closes #89, Closes #90