fix: Security stuff (#441)

* fix: Security stuff

* cr
This commit is contained in:
Brace Sproul 2025-07-17 12:19:20 -07:00 • committed by GitHub
parent 92014bdd11
commit f5513dd036
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 12 additions and 8 deletions

3
SECURITY.md Normal file
View file

@ -0,0 +1,3 @@
# Security Policy
For any security concerns, please contact us at security@langchain.dev.

View file

@ -19,9 +19,7 @@ export async function getSandboxSessionOrThrow(
} }
if (!sandboxSessionId) { if (!sandboxSessionId) {
logger.error("FAILED TO RUN COMMAND: No sandbox session ID provided", { logger.error("FAILED TO RUN COMMAND: No sandbox session ID provided");
input,
});
throw new Error("FAILED TO RUN COMMAND: No sandbox session ID provided"); throw new Error("FAILED TO RUN COMMAND: No sandbox session ID provided");
} }

View file

@ -219,7 +219,7 @@ export async function configureGitUserInRepo(
if (setRemoteOutput.exitCode !== 0) { if (setRemoteOutput.exitCode !== 0) {
logger.error(`Failed to set remote URL with token`, { logger.error(`Failed to set remote URL with token`, {
setRemoteOutput, exitCode: setRemoteOutput.exitCode,
}); });
} else { } else {
logger.info("Git remote URL updated with token successfully."); logger.info("Git remote URL updated with token successfully.");
@ -484,11 +484,10 @@ export async function cloneRepo(
} }
logger.info("Cloning repository", { logger.info("Cloning repository", {
// Don't log the full command with token for security reasons
repoPath: `${targetRepository.owner}/${targetRepository.repo}`, repoPath: `${targetRepository.owner}/${targetRepository.repo}`,
branch: branchName, branch: branchName,
baseCommit: targetRepository.baseCommit, baseCommit: targetRepository.baseCommit,
cloneCommand: gitCloneCommand.join(" "), cloneCommand: ExecuteCommandError.cleanCommand(gitCloneCommand.join(" ")),
}); });
cloneResult = await sandbox.process.executeCommand( cloneResult = await sandbox.process.executeCommand(
@ -508,7 +507,9 @@ export async function cloneRepo(
"Branch not found in upstream origin. Cloning default & checking out branch", "Branch not found in upstream origin. Cloning default & checking out branch",
{ {
targetRepository, targetRepository,
cloneDefaultBranchCommand: cloneDefaultBranchCommand.join(" "), cloneDefaultBranchCommand: ExecuteCommandError.cleanCommand(
cloneDefaultBranchCommand.join(" "),
),
}, },
); );
const cloneDefaultBranchResult = await sandbox.process.executeCommand( const cloneDefaultBranchResult = await sandbox.process.executeCommand(
@ -517,7 +518,9 @@ export async function cloneRepo(
if (cloneDefaultBranchResult.exitCode !== 0) { if (cloneDefaultBranchResult.exitCode !== 0) {
logger.error("Failed to clone default branch", { logger.error("Failed to clone default branch", {
targetRepository, targetRepository,
cloneDefaultBranchCommand: cloneDefaultBranchCommand.join(" "), cloneDefaultBranchCommand: ExecuteCommandError.cleanCommand(
cloneDefaultBranchCommand.join(" "),
),
}); });
throw new ExecuteCommandError( throw new ExecuteCommandError(
cloneDefaultBranchCommand.join(" "), cloneDefaultBranchCommand.join(" "),