Pavan Kumar Gondhi
|
50f4440c96
|
Enforce inline shell wrapper payload matching [AI] (#80978)
* fix: enforce inline shell wrapper payload matching
* addressing review-skill
* addressing codex review
* addressing codex review
* addressing claude review
* addressing claude review
* fix: complete shell wrapper allowlist handling
* addressing codex review
* addressing codex review
* addressing codex review
* addressing codex review
* addressing codex review
* addressing ci
* docs: add changelog entry for PR merge
|
2026-05-12 19:30:18 +05:30 |
|
Pavan Kumar Gondhi
|
de47989731
|
Recognize PowerShell -ec inline commands [AI] (#80893)
* fix: recognize PowerShell -ec inline command flag
* fix: recognize PowerShell -ec inline command flag
* addressing codex review
* addressing codex review
* addressing codex review
* addressing codex review
* addressing codex review
* fix: recognize PowerShell encoded command prefixes
* addressing review-skill
* addressing review-skill
* addressing codex review
* addressing codex review
* docs: add changelog entry for PR merge
|
2026-05-12 15:53:10 +05:30 |
|
Shakker
|
7d5cfd157a
|
test: tighten infra sdk empty array assertions
|
2026-05-09 05:36:12 +01:00 |
|
Pavan Kumar Gondhi
|
fc065b2693
|
Harden macOS shell wrapper allowlist parsing [AI] (#78518)
* fix: harden shell wrapper allowlist parsing
* fix: harden shell wrapper approval binding
* docs: add changelog entry for PR merge
---------
Co-authored-by: Ishaan <ishaan@Ishaans-Mac-mini.local>
|
2026-05-08 10:18:41 +05:30 |
|
Vincent Koc
|
730ba40763
|
fix(exec): unwrap arch and xcrun dispatch wrappers (#58203)
* fix(exec): unwrap arch and xcrun dispatch wrappers
* fix(infra): scope arch wrapper unwrapping to macos
* fix(exec): scope arch wrapper unwrapping to macos
* fix(infra): validate macos arch wrapper selectors
* test(infra): cover invalid arch name wrappers
|
2026-03-31 21:00:14 +09:00 |
|
Peter Steinberger
|
0b013bdd94
|
test: dedupe exec approval and system run suites
|
2026-03-28 00:02:09 +00:00 |
|
Peter Steinberger
|
2083b0581d
|
test: tighten system run command normalization coverage
|
2026-03-14 00:42:13 +00:00 |
|
Peter Steinberger
|
767609532f
|
test: tighten system run command coverage
|
2026-03-14 00:30:20 +00:00 |
|
Peter Steinberger
|
28a49aaa34
|
fix: harden powershell wrapper detection
|
2026-03-13 20:37:38 +00:00 |
|
Peter Steinberger
|
68c674d37c
|
refactor(security): simplify system.run approval model
|
2026-03-11 01:43:06 +00:00 |
|
Peter Steinberger
|
7289c19f1a
|
fix(security): bind system.run approvals to exact argv text
|
2026-03-11 01:25:31 +00:00 |
|
Peter Steinberger
|
8a469a12b2
|
test(exec): dedupe wrapper boundary regressions
|
2026-03-08 00:12:08 +00:00 |
|
Peter Steinberger
|
2fc95a7cfc
|
fix(exec): close dispatch-wrapper boundary drift
|
2026-03-07 23:40:38 +00:00 |
|
Peter Steinberger
|
1d1757b16f
|
fix(exec): recognize PowerShell encoded commands
|
2026-03-07 23:15:46 +00:00 |
|
Peter Steinberger
|
03e689fc89
|
fix(security): bind system.run approvals to argv identity
|
2026-02-26 03:41:31 +01:00 |
|
Peter Steinberger
|
0f0a680d3d
|
fix(exec): block shell-wrapper positional argv approval smuggling
|
2026-02-24 15:17:03 +00:00 |
|
Peter Steinberger
|
a67689a7e3
|
fix: harden allow-always shell multiplexer wrapper handling
|
2026-02-24 03:06:51 +00:00 |
|
Brian Mendonca
|
bd8b9af9a7
|
fix(exec): bind env-prefixed shell wrappers to full approval text
(cherry picked from commit 1edf957988)
|
2026-02-23 18:56:14 +00:00 |
|
Peter Steinberger
|
24c954d972
|
fix(security): harden allow-always wrapper persistence
|
2026-02-22 22:55:33 +01:00 |
|
Peter Steinberger
|
2b63592be5
|
fix: harden exec allowlist wrapper resolution
|
2026-02-22 09:52:02 +01:00 |
|
Peter Steinberger
|
b109fa53ea
|
refactor(core): dedupe gateway runtime and config tests
|
2026-02-22 07:44:57 +00:00 |
|
Peter Steinberger
|
6007941f04
|
fix(security): harden and refactor system.run command resolution
|
2026-02-21 11:49:38 +01:00 |
|
Peter Steinberger
|
cb3290fca3
|
fix(node-host): enforce system.run rawCommand/argv consistency
|
2026-02-14 18:53:23 +01:00 |
|