Address security-review F1/F3: the workflow re-check used a POSIX [[:cntrl:]] grep (missed the C1 range the box-side sanitizer strips) and wc -m (byte count, not chars). Replace both with a single python3 check whose accept condition is byte-for-byte identical to sanitize_pr_title — rejects [\x00-\x1f\x7f-\x9f] and caps at 70 characters — so the defense-in-depth re-validation genuinely matches the box path. |
||
|---|---|---|
| .. | ||
| agent-team-apply-verify.yml | ||
| ci-web.yaml | ||
| ci.yaml | ||
| dependency-review.yml | ||
| labeler.yml | ||