This repository has been archived by the owner on Sep 23, 2019. It is now read-only.
forked from sociomantic-tsunami/git-hub
-
Notifications
You must be signed in to change notification settings - Fork 1
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Validate received URLs before cloning
A malicious GitHub server could send an URL with the form `ext::<command>` and that would run arbitrary code where the git-hub command is ran. To avoid surprises, a simple heuristic is used to spot fishy URLs (including any `<transport>::` URL or URLs that don't match the urltype requested). This should fix most of sociomantic-tsunami#197.
- Loading branch information
1 parent
7f0f9d8
commit 3fb02d1
Showing
1 changed file
with
39 additions
and
6 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters