From f5513dd0364ad80c248dd7d36bf2b3ca62a401fa Mon Sep 17 00:00:00 2001 From: Brace Sproul Date: Thu, 17 Jul 2025 12:19:20 -0700 Subject: [PATCH] fix: Security stuff (#441) * fix: Security stuff * cr --- SECURITY.md | 3 +++ apps/open-swe/src/tools/utils/get-sandbox-id.ts | 4 +--- apps/open-swe/src/utils/github/git.ts | 13 ++++++++----- 3 files changed, 12 insertions(+), 8 deletions(-) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..f2414c9c --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,3 @@ +# Security Policy + +For any security concerns, please contact us at security@langchain.dev. diff --git a/apps/open-swe/src/tools/utils/get-sandbox-id.ts b/apps/open-swe/src/tools/utils/get-sandbox-id.ts index 7118015e..f3c208fb 100644 --- a/apps/open-swe/src/tools/utils/get-sandbox-id.ts +++ b/apps/open-swe/src/tools/utils/get-sandbox-id.ts @@ -19,9 +19,7 @@ export async function getSandboxSessionOrThrow( } if (!sandboxSessionId) { - logger.error("FAILED TO RUN COMMAND: No sandbox session ID provided", { - input, - }); + logger.error("FAILED TO RUN COMMAND: No sandbox session ID provided"); throw new Error("FAILED TO RUN COMMAND: No sandbox session ID provided"); } diff --git a/apps/open-swe/src/utils/github/git.ts b/apps/open-swe/src/utils/github/git.ts index 52c476fd..73df3ef8 100644 --- a/apps/open-swe/src/utils/github/git.ts +++ b/apps/open-swe/src/utils/github/git.ts @@ -219,7 +219,7 @@ export async function configureGitUserInRepo( if (setRemoteOutput.exitCode !== 0) { logger.error(`Failed to set remote URL with token`, { - setRemoteOutput, + exitCode: setRemoteOutput.exitCode, }); } else { logger.info("Git remote URL updated with token successfully."); @@ -484,11 +484,10 @@ export async function cloneRepo( } logger.info("Cloning repository", { - // Don't log the full command with token for security reasons repoPath: `${targetRepository.owner}/${targetRepository.repo}`, branch: branchName, baseCommit: targetRepository.baseCommit, - cloneCommand: gitCloneCommand.join(" "), + cloneCommand: ExecuteCommandError.cleanCommand(gitCloneCommand.join(" ")), }); cloneResult = await sandbox.process.executeCommand( @@ -508,7 +507,9 @@ export async function cloneRepo( "Branch not found in upstream origin. Cloning default & checking out branch", { targetRepository, - cloneDefaultBranchCommand: cloneDefaultBranchCommand.join(" "), + cloneDefaultBranchCommand: ExecuteCommandError.cleanCommand( + cloneDefaultBranchCommand.join(" "), + ), }, ); const cloneDefaultBranchResult = await sandbox.process.executeCommand( @@ -517,7 +518,9 @@ export async function cloneRepo( if (cloneDefaultBranchResult.exitCode !== 0) { logger.error("Failed to clone default branch", { targetRepository, - cloneDefaultBranchCommand: cloneDefaultBranchCommand.join(" "), + cloneDefaultBranchCommand: ExecuteCommandError.cleanCommand( + cloneDefaultBranchCommand.join(" "), + ), }); throw new ExecuteCommandError( cloneDefaultBranchCommand.join(" "),