Add initial PowerShell OSS bounty audit notes and local repro fixtures - #1
Open
kajf wants to merge 2 commits into
Open
Add initial PowerShell OSS bounty audit notes and local repro fixtures#1kajf wants to merge 2 commits into
kajf wants to merge 2 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
PowerShell/PowerShellby documenting scope, environment, and first-pass triage findings.Description
research/powershell-oss-bounty-initial-audit.mdwith scope, setup commands, attack-surface map, ranked code-paths, dead ends, and next steps.research/repros/:module-path-shadowing.ps1,new-temporary-file-permissions.ps1, andremoting-proxy-temp-path-shape.ps1..gitignoreentry to exclude the localupstream/clone used for builds and research artifacts.Testing
Start-PSBuild -UseNuGetOrg -NoPSModuleRestore, producingpwshatsrc/powershell-unix/.../publish/pwsh. (succeeded)pwshusingresearch/repros/module-path-shadowing.ps1and observed expected PSModulePath precedence behavior. (succeeded)pwshusingresearch/repros/new-temporary-file-permissions.ps1and confirmed Unix mode600for created temp files. (succeeded)research/repros/remoting-proxy-temp-path-shape.ps1to record observations aboutRemoteDiscoveryHelper.GetModulePathbehavior. (succeeded)Start-PSPesterrun but both were blocked by environment proxy failures when restoring PowerShell Gallery dependencies (HTTP 403) so those flows did not complete. (blocked)Codex Task