Skip to content

Commit 9d7723f

Browse files
authored
fix(security): resolve open Dependabot and CodeQL alerts (#21)
1 parent bf94d0c commit 9d7723f

8 files changed

Lines changed: 214 additions & 199 deletions

File tree

docs/package.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323
"@tailwindcss/vite": "^4.3.2",
2424
"@tanstack/react-query": "^5.90.12",
2525
"ai": "^6.0.199",
26-
"astro": "^7.0.6",
26+
"astro": "^7.1.3",
2727
"class-variance-authority": "^0.7.1",
2828
"clsx": "^2.1.1",
2929
"dompurify": "^3.4.7",
@@ -42,6 +42,10 @@
4242
"@types/react": "^18.3.28",
4343
"@types/react-dom": "^18.3.7",
4444
"typescript": "~6.0.3"
45+
},
46+
"pnpm": {
47+
"overrides": {
48+
"js-yaml": ">=4.3.0"
49+
}
4550
}
4651
}
47-

docs/pnpm-lock.yaml

Lines changed: 189 additions & 186 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

go.mod

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -265,7 +265,7 @@ require (
265265
github.com/prometheus/client_model v0.6.2 // indirect
266266
github.com/prometheus/common v0.67.5 // indirect
267267
github.com/prometheus/procfs v0.20.1 // indirect
268-
github.com/richardlehane/mscfb v1.0.6 // indirect
268+
github.com/richardlehane/mscfb v1.0.7 // indirect
269269
github.com/richardlehane/msoleps v1.0.6 // indirect
270270
github.com/rivo/uniseg v0.4.7 // indirect
271271
github.com/robertkrimen/otto v0.5.1 // indirect
@@ -304,7 +304,7 @@ require (
304304
github.com/xeipuuv/gojsonschema v1.2.0
305305
github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e // indirect
306306
github.com/xuri/efp v0.0.1 // indirect
307-
github.com/xuri/excelize/v2 v2.10.1 // indirect
307+
github.com/xuri/excelize/v2 v2.11.0 // indirect
308308
github.com/xuri/nfp v0.0.2-0.20250530014748-2ddeb826f9a9 // indirect
309309
github.com/yosida95/uritemplate/v3 v3.0.2 // indirect
310310
github.com/yuin/gopher-lua v1.1.1 // indirect

go.sum

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -617,8 +617,8 @@ github.com/prometheus/common v0.67.5 h1:pIgK94WWlQt1WLwAC5j2ynLaBRDiinoAb86HZHTU
617617
github.com/prometheus/common v0.67.5/go.mod h1:SjE/0MzDEEAyrdr5Gqc6G+sXI67maCxzaT3A2+HqjUw=
618618
github.com/prometheus/procfs v0.20.1 h1:XwbrGOIplXW/AU3YhIhLODXMJYyC1isLFfYCsTEycfc=
619619
github.com/prometheus/procfs v0.20.1/go.mod h1:o9EMBZGRyvDrSPH1RqdxhojkuXstoe4UlK79eF5TGGo=
620-
github.com/richardlehane/mscfb v1.0.6 h1:eN3bvvZCp00bs7Zf52bxNwAx5lJDBK1tCuH19qq5aC8=
621-
github.com/richardlehane/mscfb v1.0.6/go.mod h1:pe0+IUIc0AHh0+teNzBlJCtSyZdFOGgV4ZK9bsoV+Jo=
620+
github.com/richardlehane/mscfb v1.0.7 h1:oeoiM0WE79vHwE8RpIYYvIAc8ajTH2mb6UZm55/+EB0=
621+
github.com/richardlehane/mscfb v1.0.7/go.mod h1:pe0+IUIc0AHh0+teNzBlJCtSyZdFOGgV4ZK9bsoV+Jo=
622622
github.com/richardlehane/msoleps v1.0.6 h1:9BvkpjvD+iUBalUY4esMwv6uBkfOip/Lzvd93jvR9gg=
623623
github.com/richardlehane/msoleps v1.0.6/go.mod h1:BWev5JBpU9Ko2WAgmZEuiz4/u3ZYTKbjLycmwiWUfWg=
624624
github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ=
@@ -739,8 +739,8 @@ github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e h1:JVG44RsyaB9T2KIHavM
739739
github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e/go.mod h1:RbqR21r5mrJuqunuUZ/Dhy/avygyECGrLceyNeo4LiM=
740740
github.com/xuri/efp v0.0.1 h1:fws5Rv3myXyYni8uwj2qKjVaRP30PdjeYe2Y6FDsCL8=
741741
github.com/xuri/efp v0.0.1/go.mod h1:ybY/Jr0T0GTCnYjKqmdwxyxn2BQf2RcQIIvex5QldPI=
742-
github.com/xuri/excelize/v2 v2.10.1 h1:V62UlqopMqha3kOpnlHy2CcRVw1V8E63jFoWUmMzxN0=
743-
github.com/xuri/excelize/v2 v2.10.1/go.mod h1:iG5tARpgaEeIhTqt3/fgXCGoBRt4hNXgCp3tfXKoOIc=
742+
github.com/xuri/excelize/v2 v2.11.0 h1:HxaEFl6sRN2+8J5a8HaKq+0M4FsjBGMnWWtjOCPSG88=
743+
github.com/xuri/excelize/v2 v2.11.0/go.mod h1:jxFLbzaIwGQ5ufFNvYfUOHqXhfPaNmP14KWfmNz2Uak=
744744
github.com/xuri/nfp v0.0.2-0.20250530014748-2ddeb826f9a9 h1:+C0TIdyyYmzadGaL/HBLbf3WdLgC29pgyhTjAT/0nuE=
745745
github.com/xuri/nfp v0.0.2-0.20250530014748-2ddeb826f9a9/go.mod h1:WwHg+CVyzlv/TX9xqBFXEZAuxOPxn2k1GNHwG41IIUQ=
746746
github.com/xyproto/randomstring v1.0.5 h1:YtlWPoRdgMu3NZtP45drfy1GKoojuR7hmRcnhZqKjWU=

pkg/cli/ai.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,10 +13,10 @@ import (
1313
"github.com/flanksource/captain/pkg/ai/middleware"
1414
"github.com/flanksource/captain/pkg/ai/pricing"
1515
"github.com/flanksource/captain/pkg/api"
16-
"github.com/flanksource/captain/pkg/collections"
1716
"github.com/flanksource/captain/pkg/captainconfig"
1817
"github.com/flanksource/captain/pkg/claude"
1918
"github.com/flanksource/captain/pkg/claude/tools"
19+
"github.com/flanksource/captain/pkg/collections"
2020
dbcontext "github.com/flanksource/commons-db/context"
2121
"github.com/flanksource/commons-db/shell"
2222
)

pkg/cli/permission_catalog.go

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,12 @@ func resolveCatalogDir(baseCwd, dir string) (string, error) {
4646
return base, nil
4747
}
4848

49+
// Reject traversal sequences in the raw input before any path is built;
50+
// the prefix check below is defense in depth.
51+
if strings.Contains(dir, "..") {
52+
return "", fmt.Errorf("dir %q contains a path traversal sequence", dir)
53+
}
54+
4955
target := dir
5056
if !filepath.IsAbs(target) {
5157
target = filepath.Join(base, target)

pkg/cli/permission_catalog_test.go

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,10 +63,12 @@ func TestResolveCatalogDir(t *testing.T) {
6363
t.Fatalf("relative dir: got %q err %v, want %q", got, err, nested)
6464
}
6565

66-
// Traversal attempts must be rejected.
66+
// Traversal attempts must be rejected, including ".." segments that would
67+
// still resolve inside the workspace.
6768
for _, dir := range []string{
6869
"../../etc",
6970
filepath.Join("sub", "..", "..", "etc"),
71+
"sub/../sub/child",
7072
"/etc",
7173
} {
7274
if got, err := resolveCatalogDir(base, dir); err == nil {

pkg/cli/prompt_run_stream.go

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -171,9 +171,9 @@ func (b *runBroker) prune(maxAge time.Duration) {
171171

172172
type promptRunSnapshotBody struct {
173173
Entries []session.Message `json:"entries"`
174-
Done bool `json:"done"`
175-
Summary *PromptRunSummary `json:"summary,omitempty"`
176-
Error string `json:"error,omitempty"`
174+
Done bool `json:"done"`
175+
Summary *PromptRunSummary `json:"summary,omitempty"`
176+
Error string `json:"error,omitempty"`
177177
}
178178

179179
// handlePromptRunStream streams a run's session.Message frames as SSE:

0 commit comments

Comments
 (0)