Security release
This patch fixes GHSA-g6fq-295f-rrcx and hardens the LAP CLI release pipeline.
Security fixes
- Replace shell-interpolated browser launching with shell-free process execution.
- Validate registry-provided authentication URLs before opening them.
- Require HTTPS registry URLs except for real loopback development hosts.
- Reject URL credentials, malformed registry URLs, and prefix-bypass payloads.
- Stop privileged issue-automation runners from fetching reporter-controlled URLs.
Supply-chain hardening
- Update
js-yamlto the patched dependency range. - Pin GitHub Actions to reviewed commit SHAs.
- Add Dependabot configuration and least-privilege workflow permissions.
Both the npm package @lap-platform/lapsh and the PyPI package lapsh are released as version 0.7.1.