Skip to content

Conversation

@labkey-jeckels
Copy link
Contributor

@labkey-jeckels labkey-jeckels commented Aug 27, 2025

Rationale

Module ZIPs and their JAR contents are inherently trusted, but we can still follow best practices for unzipping

Changes

  • Check to make sure ZIP entry doesn't escape its parent

@labkey-jeckels labkey-jeckels self-assigned this Aug 27, 2025
@labkey-jeckels labkey-jeckels requested a review from a team August 27, 2025 16:57
@labkey-jeckels labkey-jeckels marked this pull request as ready for review August 27, 2025 16:57
@labkey-jeckels labkey-jeckels merged commit 52c507b into develop Aug 28, 2025
9 checks passed
@labkey-jeckels labkey-jeckels deleted the fb_warningCleanup branch August 28, 2025 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants