Peter Steinberger
|
e27bbe4982
|
fix(exec): block dangerous override-only env pivots
|
2026-03-07 19:18:05 +00:00 |
|
Peter Steinberger
|
4894d907fa
|
refactor(exec-approvals): unify system.run binding and generate host env policy
|
2026-02-26 16:58:01 +01:00 |
|
Peter Steinberger
|
9a4b2266cc
|
fix(security): bind node system.run approvals to env
|
2026-02-26 16:38:07 +01:00 |
|
Peter Steinberger
|
e80c803fa8
|
fix(security): block shell env allowlist bypass in system.run
|
2026-02-22 12:47:05 +01:00 |
|
Peter Steinberger
|
c2c7114ed3
|
fix(security): block HOME and ZDOTDIR env override injection
|
2026-02-22 09:42:55 +01:00 |
|
Peter Steinberger
|
25e89cc863
|
fix(security): harden shell env fallback
|
2026-02-21 20:01:08 +01:00 |
|
Peter Steinberger
|
5da03e6221
|
fix(macos): harden exec allowlist shell-chain checks
|
2026-02-21 16:27:18 +01:00 |
|
Peter Steinberger
|
f202e73077
|
refactor(security): centralize host env policy and harden env ingestion
|
2026-02-21 13:04:39 +01:00 |
|
Peter Steinberger
|
2cdbadee1f
|
fix(security): block startup-file env injection across host execution paths
|
2026-02-21 11:44:20 +01:00 |
|