summaryrefslogtreecommitdiff
path: root/docs/configuration/service/md-https.md
diff options
context:
space:
mode:
authorYuriy Andamasov <yuriy@vyos.io>2026-05-11 01:39:36 +0300
committerYuriy Andamasov <yuriy@vyos.io>2026-05-11 01:39:36 +0300
commit5a9d1a5d5f0897b7b3f2719bf0b5c091f217defe (patch)
tree3a61ee95d163df7009aee617c7a1d3286fca48ab /docs/configuration/service/md-https.md
parent1ddb0201310b01ecfe92fa58063dd039916e83c1 (diff)
downloadvyos-documentation-5a9d1a5d5f0897b7b3f2719bf0b5c091f217defe.tar.gz
vyos-documentation-5a9d1a5d5f0897b7b3f2719bf0b5c091f217defe.zip
ci(ai-validation): fail-fast on traversal paths (consistency w/ non-regular guard)
Copilot finding on PR #1959 (line 114): the path-traversal hardening block used `continue` (skip-with-warning) on detection of absolute / traversal paths, but the non-regular-tree-entry check below uses `exit 1`. The asymmetry meant a fork PR that smuggles in a path like `docs/../../outside.md` would silently bypass Pass 1 (no file copied into _changed_md/) and Pass 2 (LLM Read/Glob/Grep tools see no content) — reducing validation coverage on exactly the inputs that warrant the closest look. Change `continue` to `exit 1` so both unsafe-input checks have consistent visible-failure semantics. Maintainers must explicitly address an offending path rather than have it skipped. Mirrored byte-identically across all three open workflow PRs.
Diffstat (limited to 'docs/configuration/service/md-https.md')
0 files changed, 0 insertions, 0 deletions