mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
Follow-up hardening from the security re-verification of the prior fix: - H6: the parser's wrapper skip-loop skipped a wrapper's option flag but not its space-separated value, so `nice -n 10 git push`, `sudo -u ci git push`, `timeout 5 git push` (and wrappers outside the set) returned None and ran unguarded. Rewrite `_parse_git_tokens` to locate the `git` executable and fail closed on any unrecognized leading token before a git push, instead of a silent pass-through. - H1: `git remote get-url --push` returns only the first of multiple pushurl entries while `git push` writes to ALL of them, and insteadOf/pushInsteadOf can rewrite the destination. Use `get-url --push --all` and fail closed unless there is exactly one push URL and no URL rewrite is configured. Adds tests for valued-wrapper-option pushes, multiple push URLs, and URL rewrites. Claude-Session: https://claude.ai/code/session_01GxSndB7VoGQyeS196eUr5E |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| check_message_queue.py | ||
| ensure_no_empty_msg.py | ||
| exclude_tools.py | ||
| model_fallback.py | ||
| notify_step_limit.py | ||
| plan_mode.py | ||
| refresh_github_proxy.py | ||
| refresh_slack_status.py | ||
| repair_orphaned_tool_calls.py | ||
| sandbox_circuit_breaker.py | ||
| sanitize_thinking_blocks.py | ||
| sanitize_tool_inputs.py | ||
| settle_review_check.py | ||
| tool_artifact.py | ||
| tool_error_handler.py | ||
| workflow_push_guard.py | ||