Skip to content

fix(security): block repo-configured exec during scans + release hardening - #37

Merged
Bharath-code merged 3 commits into
mainfrom
fix/week1-hardening
Sep 25, 2026
Merged

Bharath-code merged 3 commits into
mainfrom
fix/week1-hardening

Conversation

@Bharath-code

Copy link
Copy Markdown
Owner

Summary

  • Security: git status runs the program named by a repo's core.fsmonitor, so scanning a folder containing a crafted repo (for example an unzipped archive) could execute arbitrary code. All git calls now go through gitstatus.Command, which sets -c core.fsmonitor=false, --no-optional-locks (status no longer rewrites .git/index) and GIT_TERMINAL_PROMPT=0. A regression test uses a real fsmonitor hook.
  • Installer: verifies SHA-256 against checksums.txt; curl -f so HTTP errors fail instead of installing an error page.
  • Version stamp: main.version was a const, so -ldflags -X was ignored and every release reported 1.0.1. Now a var; the star nudge uses the running version.
  • CI/release: release actions pinned to SHAs, GoReleaser pinned to v2.18.2, govulncheck step, Dependabot for gomod + actions.
  • CHANGELOG entry for 1.4.0.

Test plan

  • go test -race ./... passes; new TestStatus_IgnoresRepoFsmonitor failed before the fix
  • go vet, gofmt, govulncheck v1.8.0 clean
  • Installer run end-to-end against v1.3.1 (verified), and with a tampered hash (rejected)
  • go build -ldflags "-X main.version=9.9.9" reports 9.9.9

Known trade-off: bulk fetch (F) still honours per-repo core.sshCommand so custom SSH setups keep working. Scans never run it.

🤖 Generated with Claude Code

Bharath-code and others added 2 commits September 25, 2026 23:44
git status runs the program named by core.fsmonitor, so scanning a folder
containing a crafted repo could execute arbitrary code. All git calls now go
through gitstatus.Command, which sets -c core.fsmonitor=false,
--no-optional-locks (status no longer rewrites .git/index) and
GIT_TERMINAL_PROMPT=0. Adds a regression test with a real fsmonitor hook.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- install.sh verifies SHA-256 against checksums.txt; curl fails on HTTP errors
- main.version is now a var so -ldflags -X works (every release said 1.0.1)
- nudge uses the running version instead of a stale constant
- release workflow: actions pinned to SHAs, GoReleaser pinned to v2.18.2
- CI: govulncheck step; Dependabot for gomod and github-actions
- CHANGELOG entry for 1.4.0

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kilo-code-bot

kilo-code-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown

Kilo Code Review could not run — your account is out of credits.

Add credits or switch to a free model to enable reviews on this change.

CI and GoReleaser built with go1.26.0, whose os package is affected by
GO-2026-4602 (reachable via workspace.CompleteDirectoryPath). The toolchain
directive makes builds use 1.26.8 while keeping go 1.26.0 as the minimum.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Bharath-code
Bharath-code merged commit d165cad into main Sep 25, 2026
3 of 4 checks passed
@Bharath-code
Bharath-code deleted the fix/week1-hardening branch September 25, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant