9.0.0-beta.1
Pre-release
Pre-release
·
2 commits
to beta/v9.0.0
since this release
Security
- Prevent path traversal attacks in config file handlers for directory and YAML contexts. [#1418]
Breaking change: Previously, file references using absolute paths or ../ paths outside the config root would log a deprecation warning but still load. They now throw an error and halt execution.
Who is impacted: Users whose YAML or directory configs reference files with absolute paths (e.g. script: /etc/scripts/my-script.js) or paths that traverse outside the config root (e.g. script: ../../shared/scripts/my-script.js) must update those references to use paths relative to the config directory before upgrading.