Repository navigation
v0.2.5: Security Hardening
Security Hardening Release
Changes
- Input validation (8.1): exec_in_container command/working_dir/env regex validation
- Path validation (8.2): build_image context path rejects URLs, enforces absolute local paths
- Output sanitization (8.3): sanitizeOutput helper strips ANSI escapes, invisible Unicode, Docker stream headers
- Size caps (8.4): logs 100KB, general 1MB, schema bounds on tail/pattern/containers
- Timeout caps (8.6): watch_health 600s, watch_events 300s
- Security policy (8.8): SECURITY.md with threat model and disclosure process
- README expansion (8.10): Threat model, hardening details, SECURITY.md link
Security Notes
This release implements 6 findings from a security audit. All tool inputs are now validated against allowlists. Output is sanitized to prevent injection attacks. Resource consumption is bounded.