Skip to content

v2.14.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 12:33
· 22 commits to main since this release
10964eb

Security

  • Fixes GHSA-972x-g47g-3922 (high): a Windows path written with backslashes hid an interpreter from the command classifier, so the program it carried was not read.

Minor Changes

  • 2f13e7c Thanks @tufantunc! - Policy: command classification reads a command under both shell dialects a target host may run — POSIX and cmd.exe — and holds it to the stricter reading when they disagree, instead of assuming the POSIX one. Path stripping now accepts backslash-separated command words, and quote removal inside double quotes follows POSIX byte for byte (a backslash before an ordinary character is kept). Commands without a backslash classify exactly as before. One deliberate change within that: a name written inside quotes with backslashes keeps its bytes now and classifies as the name a shell would actually pass in argv, where before the backslashes were silently removed.