PR review artifacts now reject repository names like "." or ".." that could escape paths.
What's wrong with this entry?
Repository names read back from published review artifacts could be . or .., a path-traversal risk; they are now rejected.
- The regex used to validate PR review anchors and the review JSON schema changed from
/^[A-Za-z0-9._-]{1,100}$/to a form with a leading negative lookahead - A repo named
.or..now fails with "anchor.repo is not a valid repository name"
anchor.repo is not a valid repository name
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.221
Cloud review: better messages for detached HEAD and wrong base branch
Both mention code review
-
v2.1.223
Cloud review failure message points at plain /code-review
Both mention code review
-
v2.1.239
Code review findings now carry a short summary and a category
Both mention code review