Skip to content

CM-73340 dev x fix cli ide vulnerabilities batch - #162

Merged
omer-roth merged 6 commits into
mainfrom
CM-73340-dev-x-fix-cli-ide-vulnerabilities-batch
Sep 24, 2026
Merged

omer-roth merged 6 commits into
mainfrom
CM-73340-dev-x-fix-cli-ide-vulnerabilities-batch

Conversation

@omer-roth

Copy link
Copy Markdown
Collaborator

No description provided.

omer-roth and others added 3 commits September 24, 2026 16:28
- Run the CLI without a shell to prevent command injection via scan paths and ignore values
- Restrict CLI related settings to machine scope and declare limited untrusted workspace support
- Add CSP to webviews, sanitize rendered markdown and escape CWE/CVE links
- Bundle diff2html locally instead of loading it from CDN
- Verify macOS CLI files before first use
- Fix swapped ignore by rule/path options
- Stop logging CLI output that may contain detected secrets
- Remove unused shelljs, @types/shelljs and semver
- Bump @typescript-eslint/parser, typescript-eslint, @types/node and mocha

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Comment thread src/utils/file-checksum.ts
Comment thread src/services/cli-download-service.ts Outdated
Comment thread src/utils/file-checksum.ts
Comment thread src/services/cli-download-service.ts Outdated
@doratias18 doratias18 changed the title Cm 73340 dev x fix cli ide vulnerabilities batch CM-73340 dev x fix cli ide vulnerabilities batch Sep 24, 2026
Comment thread src/utils/file-checksum.ts
Comment thread src/services/cli-download-service.ts Outdated
Comment thread src/utils/file-checksum.ts
Comment thread src/services/cli-download-service.ts
Comment thread src/services/cli-download-service.ts
Comment thread src/services/cli-download-service.ts
Comment thread src/services/cli-download-service.ts
@omer-roth
omer-roth merged commit f3dcce9 into main Sep 24, 2026
6 checks passed
@omer-roth
omer-roth deleted the CM-73340-dev-x-fix-cli-ide-vulnerabilities-batch branch September 24, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant