Skip to content

Conversation

@tnotheis
Copy link
Member

@tnotheis tnotheis commented Dec 3, 2025

Readiness checklist

  • I added/updated unit tests.
  • I added/updated integration tests.
  • I ensured that the PR title is good enough for the changelog.
  • I labeled the PR.

We didn't use that possibility anyway, and our pentester complained about the fact that we used the input from the EnvironmentName environment variable for configuring file access without checking for the environment variable's content first, which could, in theory, enable an attack.

@tnotheis tnotheis requested a review from erbenjak December 3, 2025 06:07
@tnotheis tnotheis self-assigned this Dec 3, 2025
@tnotheis tnotheis added the chore Some routine work like updating dependencies label Dec 3, 2025
@tnotheis tnotheis enabled auto-merge (squash) December 3, 2025 06:09
@tnotheis tnotheis merged commit b1996e4 into main Dec 3, 2025
25 checks passed
@tnotheis tnotheis deleted the remove-possibility-to-use-environment-specific-config-files branch December 3, 2025 08:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Some routine work like updating dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants