Skip to content

[2.0.x] bport: Harden Windows VCS URI fragments against command injection #8970

Merged
eed3si9n merged 2 commits intosbt:2.0.xfrom
eed3si9n:bport/cve-fix
Mar 24, 2026
Merged

[2.0.x] bport: Harden Windows VCS URI fragments against command injection #8970
eed3si9n merged 2 commits intosbt:2.0.xfrom
eed3si9n:bport/cve-fix

Conversation

@eed3si9n
Copy link
Copy Markdown
Member

No description provided.

- Use Process(argv) for git/hg/svn without cmd /c on Windows
- Add VcsUriFragment.validate for fragments in clone/checkout/update
- Add tests
@eed3si9n eed3si9n merged commit 3d22453 into sbt:2.0.x Mar 24, 2026
15 checks passed
@eed3si9n eed3si9n deleted the bport/cve-fix branch March 24, 2026 03:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants