Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): do not allow to read files above #1771

Merged
merged 14 commits into from Mar 19, 2024

Conversation

alexander-akait
Copy link
Member

This PR contains a:

  • bugfix
  • new feature
  • code refactor
  • test update
  • documentation update
  • typo fix
  • metadata update

Motivation / Use-Case

internal report

Breaking Changes

No

Additional Info

No

Copy link

codecov bot commented Mar 19, 2024

Codecov Report

Attention: Patch coverage is 89.47368% with 2 lines in your changes are missing coverage. Please review.

Project coverage is 97.18%. Comparing base (ab533de) to head (a7a8cf3).

Files Patch % Lines
src/utils/getFilenameFromUrl.js 84.61% 2 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master    #1771      +/-   ##
==========================================
- Coverage   97.55%   97.18%   -0.38%     
==========================================
  Files          10       10              
  Lines         450      461      +11     
  Branches      134      135       +1     
==========================================
+ Hits          439      448       +9     
- Misses         10       12       +2     
  Partials        1        1              

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@alexander-akait alexander-akait merged commit e10008c into master Mar 19, 2024
12 of 14 checks passed
@alexander-akait alexander-akait deleted the fix-security-problem branch March 19, 2024 19:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant