diff options
| author | hathach <[email protected]> | 2026-06-02 10:42:39 +0700 |
|---|---|---|
| committer | hathach <[email protected]> | 2026-06-02 10:42:39 +0700 |
| commit | 6936cc630dfc0d125337e3f4f6e9322b503df3b2 (patch) | |
| tree | d3ef4b1a1c4e71b00fca9a4a011807db48686a33 /docs/reference | |
| parent | b009ddb01232192538762f21371d65a4e6d04f14 (diff) | |
ci(claude): scope Bash allowlist instead of wide-open (Codex P1)
Codex flagged that @claude can be summoned on a fork PR (the review
workflow even directs fork PRs here), so the checked-out PR content is
potentially attacker-controlled. Unrestricted Bash in this write-token +
OAuth-secret job let prompt injection steer Claude into arbitrary
shell/network commands.
Scope Bash to the repo's actual verification commands (cmake, ninja,
make, ctest, python/python3, pre-commit, clang-format, codespell, git).
This blocks the injection-to-arbitrary-command path while still letting
Claude build/test before committing. Building fork code itself is already
done by the existing CircleCI, so that surface is unchanged.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Diffstat (limited to 'docs/reference')
0 files changed, 0 insertions, 0 deletions
