Skip to content

fix(buildkite): validate github_repo_name to prevent path traversal#384

Open
jcc-google wants to merge 1 commit into
vllm-project:mainfrom
jcc-google:fix/github-path-traversal-b510375092
Open

fix(buildkite): validate github_repo_name to prevent path traversal#384
jcc-google wants to merge 1 commit into
vllm-project:mainfrom
jcc-google:fix/github-path-traversal-b510375092

Conversation

@jcc-google

Copy link
Copy Markdown
Contributor

Validate github_repo_name read from pipeline config to ensure it belongs to vllm-project organization and does not contain path traversal characters.

BUG=b/510375092
TAG=agy
CONV=f5118c4a-3577-4dc6-a4b6-1f2abb990935

Validate github_repo_name read from pipeline config to ensure it belongs
to vllm-project organization and does not contain path traversal characters.

Signed-off-by: Jincheng Chen <chenjincheng@google.com>
BUG=b/510375092
TAG=agy
CONV=f5118c4a-3577-4dc6-a4b6-1f2abb990935
@jcc-google jcc-google force-pushed the fix/github-path-traversal-b510375092 branch from 9a695b9 to 1436e04 Compare June 23, 2026 22:18
@jcc-google

Copy link
Copy Markdown
Contributor Author

@khluu I'm from Google Core ML team. Our team is working on a security scan to deal with potential security issue. Here is one of our fix. Could you please help to take a look and let me know your opinion and our path forward? Thanks.

@QiliangCui QiliangCui requested a review from khluu June 24, 2026 03:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant