Skip to content

v0.2.5: Security Hardening

Choose a tag to compare

@friendlygeorge friendlygeorge released this 13 Jun 09:37
· 40 commits to main since this release

Security Hardening Release

Changes

  • Input validation (8.1): exec_in_container command/working_dir/env regex validation
  • Path validation (8.2): build_image context path rejects URLs, enforces absolute local paths
  • Output sanitization (8.3): sanitizeOutput helper strips ANSI escapes, invisible Unicode, Docker stream headers
  • Size caps (8.4): logs 100KB, general 1MB, schema bounds on tail/pattern/containers
  • Timeout caps (8.6): watch_health 600s, watch_events 300s
  • Security policy (8.8): SECURITY.md with threat model and disclosure process
  • README expansion (8.10): Threat model, hardening details, SECURITY.md link

Security Notes

This release implements 6 findings from a security audit. All tool inputs are now validated against allowlists. Output is sanitized to prevent injection attacks. Resource consumption is bounded.