Repository navigation
Secret-file protection now looks inside scripts handed to pwsh and powershell, closing a gap where a secret read wrapped in pwsh -c was allowed at every safety level.
Changed
- Changed deeply nested
pwsh -cscripts to stop at the derived-command work limit instead of being walked without bound. (#235) - Documented in
SECURITY.mdthat findings from Anthropic's OSS Scanner are fixed privately, with a public issue opened only after the fix is released.
Fixed
- Fixed secret-file protection ignoring the script passed to
pwshorpowershell, so a read such aspwsh -c 'Get-Content ~/.ssh/config'is now blocked like the same read throughbash -c. Windows-style paths (~\.ssh\config), the-Commandspelling, leading switches such as-NoProfile, and thepwsh.exeform are all covered. (#235) - Fixed a PowerShell script being analyzed under POSIX rules when the same script text had already been parsed as POSIX earlier in the command, such as after an
eval. (#235)