Skip to content

Add dependabot config file#35

Merged
ArangoGutierrez merged 1 commit intomainfrom
dependabot
May 9, 2024
Merged

Add dependabot config file#35
ArangoGutierrez merged 1 commit intomainfrom
dependabot

Conversation

@ArangoGutierrez
Copy link
Collaborator

No description provided.

Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
@ArangoGutierrez
Copy link
Collaborator Author

Will prevent events like #34

@ArangoGutierrez ArangoGutierrez merged commit c20b386 into main May 9, 2024
@ArangoGutierrez ArangoGutierrez deleted the dependabot branch May 9, 2024 10:09
ArangoGutierrez added a commit to ArangoGutierrez/holodeck that referenced this pull request Feb 12, 2026
…rmat

GenerateInstanceID silently returned empty string on rand failure,
producing a cache file named '.yaml'. Change to return (string, error).
Also validate instance IDs match hex format in GetInstanceCacheFile
to prevent path traversal.

Audit findings NVIDIA#8 (MEDIUM), NVIDIA#35 (LOW).

Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
ArangoGutierrez added a commit that referenced this pull request Feb 13, 2026
…rmat (#648)

GenerateInstanceID silently returned empty string on rand failure,
producing a cache file named '.yaml'. Change to return (string, error).
Also validate instance IDs match hex format in GetInstanceCacheFile
to prevent path traversal.

Audit findings #8 (MEDIUM), #35 (LOW).

Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant