Add negative test cases for path-traversal protection in update.retrieve()#44
Merged
rilma merged 2 commits intofeatures/upgrade-ci-cdfrom Feb 21, 2026
Merged
Add negative test cases for path-traversal protection in update.retrieve()#44rilma merged 2 commits intofeatures/upgrade-ci-cdfrom
update.retrieve()#44rilma merged 2 commits intofeatures/upgrade-ci-cdfrom
Conversation
…eve() Co-authored-by: rilma <14822065+rilma@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Update CI/CD pipeline based on review feedback
Add negative test cases for path-traversal protection in Feb 21, 2026
update.retrieve()
rilma
approved these changes
Feb 21, 2026
rilma
approved these changes
Feb 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The path-traversal protection in
update.retrieve()lacked test coverage for failure paths, leaving the security-sensitivesafe_extractlogic unverified against regression.Changes
_make_tarball_with_traversal— builds tar fixtures with controlled (malicious) member names for use in negative teststest_retrieve_path_traversal_raises— assertsValueErroris raised when a tar member uses a relative../escape pathtest_retrieve_absolute_path_in_tar_raises— assertsValueErroris raised when a tar member uses an absolute path (e.g./etc/passwd) outside the target directory💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.