Skip to content

Confine cache paths and harden the v0.1.2 release - #3

Merged
CAOShurong merged 1 commit into
mainfrom
codex/confine-cache-paths
Aug 11, 2026
Merged

CAOShurong merged 1 commit into
mainfrom
codex/confine-cache-paths

Conversation

@CAOShurong

Copy link
Copy Markdown
Owner

What changed

  • reject project names outside the Python packaging name grammar before any network or cache work
  • resolve every cache destination and prove it remains under the selected cache before deletion or creation
  • add regression coverage for project-name traversal, version traversal, valid names, and Unicode case-folding lookalikes
  • test Python 3.14, pin all third-party Actions, add Actions Dependabot, and attach checksums plus build provenance to releases

Why

A crafted package or version could previously make the cache path resolve outside the selected cache. If a matching directory existed there, the incomplete-cache cleanup could delete it before the network request failed.

Verified

  • 96 offline tests
  • Ruff lint and format checks
  • generated README check
  • wheel and sdist build plus strict Twine validation
  • fresh-wheel installation reports willitbreak 0.1.2
  • real compatible upgrade exits 0
  • real urllib3 breaking upgrade exits 2 and names both call sites
  • malicious name and version paths exit 1 while outside sentinel files remain intact
  • every pinned Action SHA matches its published tag

@CAOShurong
CAOShurong merged commit 89528af into main Aug 11, 2026
13 checks passed
@CAOShurong
CAOShurong deleted the codex/confine-cache-paths branch August 11, 2026 09:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant