style: apply ruff format to fix CI lint failure
CI / lint (pull_request) Successful in 36s
CI / typecheck (pull_request) Successful in 1m0s
CI / quality (pull_request) Successful in 1m26s
CI / security (pull_request) Successful in 1m55s
CI / build (pull_request) Successful in 34s
CI / helm (pull_request) Successful in 38s
CI / push-validation (pull_request) Successful in 42s
CI / unit_tests (pull_request) Successful in 5m41s
CI / integration_tests (pull_request) Successful in 9m34s
CI / docker (pull_request) Successful in 1m42s
CI / coverage (pull_request) Successful in 11m2s
CI / status-check (pull_request) Successful in 3s
CI / lint (pull_request) Successful in 36s
CI / typecheck (pull_request) Successful in 1m0s
CI / quality (pull_request) Successful in 1m26s
CI / security (pull_request) Successful in 1m55s
CI / build (pull_request) Successful in 34s
CI / helm (pull_request) Successful in 38s
CI / push-validation (pull_request) Successful in 42s
CI / unit_tests (pull_request) Successful in 5m41s
CI / integration_tests (pull_request) Successful in 9m34s
CI / docker (pull_request) Successful in 1m42s
CI / coverage (pull_request) Successful in 11m2s
CI / status-check (pull_request) Successful in 3s
This commit is contained in:
@@ -47,15 +47,15 @@ def validate_path(path_str: str, project_root: Path | None = None) -> Path:
|
||||
# Check for dangerous patterns that could be used for injection
|
||||
dangerous_patterns = [
|
||||
"..", # Path traversal
|
||||
";", # Command separator
|
||||
"|", # Pipe operator
|
||||
"&", # Background/AND operator
|
||||
"$", # Variable/command substitution
|
||||
"`", # Backtick command substitution (deprecated)
|
||||
"(", # Subshell grouping start
|
||||
")", # Subshell grouping end
|
||||
"<", # Input redirection
|
||||
">", # Output redirection
|
||||
";", # Command separator
|
||||
"|", # Pipe operator
|
||||
"&", # Background/AND operator
|
||||
"$", # Variable/command substitution
|
||||
"`", # Backtick command substitution (deprecated)
|
||||
"(", # Subshell grouping start
|
||||
")", # Subshell grouping end
|
||||
"<", # Input redirection
|
||||
">", # Output redirection
|
||||
"\n", # Newline injection
|
||||
"\r", # Carriage return injection
|
||||
"\\n", # Escaped newline injection in feature/CLI input
|
||||
@@ -86,10 +86,7 @@ def validate_path(path_str: str, project_root: Path | None = None) -> Path:
|
||||
try:
|
||||
resolved.relative_to(project_root_resolved)
|
||||
except ValueError as e:
|
||||
msg = (
|
||||
f"Path {resolved} is outside project root "
|
||||
f"{project_root_resolved}"
|
||||
)
|
||||
msg = f"Path {resolved} is outside project root {project_root_resolved}"
|
||||
raise ValueError(msg) from e
|
||||
|
||||
return resolved
|
||||
|
||||
Reference in New Issue
Block a user