Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

mldistwatch: forbid tarbombs from being indexed #392

Draft
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

rjbs
Copy link
Collaborator

@rjbs rjbs commented Apr 28, 2023

Previously, you could upload a tarball with "Foo.pm" in the root and we would index that. From now on, dists must have a top-level directory, and only that one directory.

Previously, you could upload a tarball with "Foo.pm" in the root and we
would index that.  From now on, dists must have a top-level directory,
and only that one directory.
@rjbs rjbs requested a review from andk April 28, 2023 08:11
@haarg
Copy link

haarg commented Apr 28, 2023

Does this handle a tarball with a top level '.' directory properly?

@rjbs
Copy link
Collaborator Author

rjbs commented Apr 29, 2023

No! (concluded by thinking about it, not testing)

@andk
Copy link
Owner

andk commented Apr 29, 2023

@rjbs, could you review and resolve conflicts?

@rjbs rjbs marked this pull request as draft April 30, 2023 07:52
@rjbs rjbs added the indexer How we index uploads label Apr 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
indexer How we index uploads
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants