Commit 69643bd
committed
toolbox: fix codeql go/zipslip
Updates the `archiveRead` function in the `toolbox/hgfs/archive.go` file. The change adds validation to prevent directory traversal attacks.
Signed-off-by: Ryan Johnson <ryan.johnson@broadcom.com>1 parent 410e92e commit 69643bd
1 file changed
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
238 | 238 | | |
239 | 239 | | |
240 | 240 | | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
241 | 247 | | |
242 | 248 | | |
243 | 249 | | |
| |||
0 commit comments