Skip to content

Add rattler entry point fix reference#8270

Open
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8270from
cookesan:rattler-q53q-fix-reference
Open

Add rattler entry point fix reference#8270
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8270from
cookesan:rattler-q53q-fix-reference

Conversation

@cookesan

Copy link
Copy Markdown

Adds the upstream merge commit for conda/rattler#2445 to GHSA-q53q-5r4j-5729.

Evidence checked:

  • PR [GHSA-jfh8-c2jp-5v3q] Remote code injection in Log4j #2445 merged as commit 4f06eca89aa13209774d26dbac077c41b72bac7c.
  • The rattler-v0.43.2 fixed tag contains that merge commit, and the release notes name [GHSA-jfh8-c2jp-5v3q] Remote code injection in Log4j #2445 as the entry-point traversal fix.
  • The commit validates entry-point command paths, rejects absolute paths and parent-directory escapes, and adds regression coverage for traversal and script-body injection cases.
  • The crates.io rattler 0.43.2 package and PyPI py-rattler 0.24.0 source distribution contain the fixed entry-point code.

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-8270 June 29, 2026 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant