Repository navigation
Security Hardening Release
6 security fixes from adversarial pre-ship review + sentinel review:
P2 (release-blocking):
_alert_slack_post_message: JSON-escape channel value before awk interpolation — prevents JSON injection from channel names containing"or\
P3 (defense-in-depth):
_alert_email_local: CR/LF stripping on all header values (recip, subject, from, reply-to) — prevents header injection if called outside_alert_deliver_email_alert_deliver_email: CR/LF stripping on reply-to, recip, and from in relay path — parity with local MTA path_alert_slack_upload: validate upload URL is HTTPS before uploading file content — rejects http, file, ftp schemes_alert_slack_upload: case-insensitive HTTPS validation — extended case pattern for bash 4.1 compatibility_alert_slack_upload:--data-urlencodefor filename parameter — prevents form parameter injection from filenames containing&
Testing:
- 7 new security regression tests (253 → 260 total)
- batsman submodule 1.0.3 → 1.4.0
Consumers: BFD and LMD should update their alert_lib submodule/copy to v1.0.6.