Skip to content

Hardening: Block path traversal in package install via composer.json name#237

Merged
swissspidy merged 7 commits into
mainfrom
copilot/hardening-path-traversal-issue
May 19, 2026
Merged

Hardening: Block path traversal in package install via composer.json name#237
swissspidy merged 7 commits into
mainfrom
copilot/hardening-path-traversal-issue

Fix is_child_path: resolve .. segments and use case-insensitive compa…

ab278f6
Select commit
Loading
Failed to load commit list.
Codecov / codecov/patch failed May 2, 2026 in 0s

0.00% of diff hit (target 28.20%)

View this Pull Request on Codecov

0.00% of diff hit (target 28.20%)