fix(privacy): redact Excel compatibility worksheet names - #246
Draft
seonghobae wants to merge 27 commits into
Draft
fix(privacy): redact Excel compatibility worksheet names#246seonghobae wants to merge 27 commits into
seonghobae wants to merge 27 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #245.
Closes #283.
Closes #284.
Closes #287.
Closes #314.
Protected base is independently resolved
main@e8109ec2a17de8bd6594487aa12c8c8a93cb2c03; exact branch head is5da8f0e63a79264cb3b57eb62c1a4ddc2861683a. PR API base SHA is historical.This Draft hardens Inkspan-owned local Office publication, diagnostics, and bounded request traversal: Excel compatibility worksheet names, filesystem paths, caller-controlled XML/object keys, rejected output extensions, temporary publication cleanup, accurate collision/cleanup failure classification, and DOCX rich-run preflight. Host transport/auth/tenancy/persistence/credentials/deployment/model ownership is unchanged.
Hosted RED lineage:
5146a3480258089b3d119d3396956e95128fb141, CI31605125522failed in Office tests after setup; repair startsfb09e44ee9cd4692400049766153e07b987239ae.72311561cffb67edbdd0b242ee4a4d835fb1d618, CI31610618676failed in Office tests after setup; repair5b4e484a04a0f408fbdadf54cef4a65c5cea6a4d.69ba9d1ad3145cf697ea852b6e644a9d8618dd2b, CI31649209029failed in Office tests after setup; Security31649209013and SAST31649208990succeeded; repair90114b2b80c87531f0cdf9fa9546c461260e2e47.1d41b29b8050a64cf29f1df03f214501698ade18, CI31693905857failed at the intended oversized custom-Sequence traversal boundary; repair720a8b30ee31240e4bf25410f74eb5b2b5ba6ff0preflights the 4,096-run ceiling before recursive safety traversal. Exact current head5da8f0e63a79264cb3b57eb62c1a4ddc2861683aadds defense-in-depth regressions proving non-sequence validation remains with the strict renderer and the strict renderer retains its own run-count ceiling.7fc53b653c70b37a8efb1f582d05ce4f9886fa85had successor-cancelled runs, so no hosted RED is claimed for it.Exact-head GREEN for unchanged
5da8f0e63a79264cb3b57eb62c1a4ddc2861683a: CI31694556417, Security31694556344, and SAST31694556389all succeeded; canonical CI includes root typecheck/100% owned-production coverage/package/demo, cross-engine browser evidence, and Office Python 3.11–3.14 100% branch/package gates. Formal reviews 0; unresolved review threads 0.Any head/live-base movement invalidates this proof. Keep Draft/unmerged while #118 owns the protected v0.6.0 publication/provenance boundary.