Skip to content

v1.4.511

Choose a tag to compare

@github-actions github-actions released this 04 Oct 23:34
· 4 commits to main since this release

Changes

PR #2107 by johnpippett: Security: fix remote file write and shell injection in template extensions

  • Fixed a remote arbitrary file write vulnerability by disabling automatic application of file changes when running in API mode, preventing unsupervised writes triggered through the REST API's PatternName input.
  • Replaced the weak strings.Contains(path, "..") check in the file manager with proper path containment validation that rejects absolute paths and confirms resolved paths stay within the project root.
  • Hardened the path containment check in ApplyFileChanges by using filepath.Rel, correctly handling edge cases such as a project root of /.
  • Consolidated path validation in ParseFileChanges and ApplyFileChanges to a single filepath.IsLocal call, which rejects absolute paths, empty paths, directory traversal, and Windows reserved names.
  • Added a regression test that fails if the path containment guard is removed.

PR #2187 by moritzschmitz-oviva: feat: add Eisenhower Matrix prioritization pattern

  • Added a new Eisenhower Matrix prioritization pattern for task triage and decision-making.
  • Renamed the pattern from eisenhower to eisenhower_matrix and removed the old pattern directory.
  • Relocated the Eisenhower Matrix pattern into data/patterns.
  • Registered the pattern's description and metadata with the BUSINESS, SELF, and STRATEGY tags.
  • Added task classification and a weekly planning extract to the pattern.