fix: Security stuff (#441)

* fix: Security stuff

* cr
This commit is contained in:
Brace Sproul 2025-07-17 12:19:20 -07:00 • committed by GitHub
parent 92014bdd11
commit f5513dd036
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 12 additions and 8 deletions

3
SECURITY.md Normal file
View file

@ -0,0 +1,3 @@
# Security Policy
For any security concerns, please contact us at security@langchain.dev.

View file

@ -19,9 +19,7 @@ export async function getSandboxSessionOrThrow(
}
if (!sandboxSessionId) {
logger.error("FAILED TO RUN COMMAND: No sandbox session ID provided", {
input,
});
logger.error("FAILED TO RUN COMMAND: No sandbox session ID provided");
throw new Error("FAILED TO RUN COMMAND: No sandbox session ID provided");
}

View file

@ -219,7 +219,7 @@ export async function configureGitUserInRepo(
if (setRemoteOutput.exitCode !== 0) {
logger.error(`Failed to set remote URL with token`, {
setRemoteOutput,
exitCode: setRemoteOutput.exitCode,
});
} else {
logger.info("Git remote URL updated with token successfully.");
@ -484,11 +484,10 @@ export async function cloneRepo(
}
logger.info("Cloning repository", {
// Don't log the full command with token for security reasons
repoPath: `${targetRepository.owner}/${targetRepository.repo}`,
branch: branchName,
baseCommit: targetRepository.baseCommit,
cloneCommand: gitCloneCommand.join(" "),
cloneCommand: ExecuteCommandError.cleanCommand(gitCloneCommand.join(" ")),
});
cloneResult = await sandbox.process.executeCommand(
@ -508,7 +507,9 @@ export async function cloneRepo(
"Branch not found in upstream origin. Cloning default & checking out branch",
{
targetRepository,
cloneDefaultBranchCommand: cloneDefaultBranchCommand.join(" "),
cloneDefaultBranchCommand: ExecuteCommandError.cleanCommand(
cloneDefaultBranchCommand.join(" "),
),
},
);
const cloneDefaultBranchResult = await sandbox.process.executeCommand(
@ -517,7 +518,9 @@ export async function cloneRepo(
if (cloneDefaultBranchResult.exitCode !== 0) {
logger.error("Failed to clone default branch", {
targetRepository,
cloneDefaultBranchCommand: cloneDefaultBranchCommand.join(" "),
cloneDefaultBranchCommand: ExecuteCommandError.cleanCommand(
cloneDefaultBranchCommand.join(" "),
),
});
throw new ExecuteCommandError(
cloneDefaultBranchCommand.join(" "),