Commit 93071b9
fix(security): restrict network scope to ports 80 and 443
.all(ports: []) is semantically identical to .all() in SPM — empty
array means "all ports allowed". Change to .all(ports: [80, 443])
to actually restrict the plugin to HTTP/HTTPS ports only, blocking
port scanning and access to internal services on non-standard ports.
Verified end-to-end: plugin downloads CLI v1.34.2 over port 443 and
runs scan successfully with restricted scope.
DEVA11Y-481
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent ac99746 commit 93071b9
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| |||
0 commit comments