mirror of
https://github.com/rudrankriyam/App-Store-Connect-CLI.git
synced 2026-04-25 15:45:48 +03:00
[PR #779] [MERGED] Attachment filename path traversal #780
Labels
No labels
bug
bug
documentation
enhancement
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/App-Store-Connect-CLI#780
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/rudrankriyam/App-Store-Connect-CLI/pull/779
Author: @cursor[bot]
Created: 2/25/2026
Status: ✅ Merged
Merged: 2/25/2026
Merged by: @rudrankriyam
Base:
feat/web-review-resolution← Head:cursor/attachment-filename-path-traversal-7b2b📝 Commits (1)
3cc9539Sanitize review attachment download filenames📊 Changes
2 files changed (+35 additions, -1 deletions)
View changed files
📝
internal/cli/web/web_review.go(+4 -1)➕
internal/cli/web/web_review_test.go(+31 -0)📄 Description
Summary
filepath.Baseto prevent directory traversal sequences.Validation
make formatmake lintmake testWall of Apps (only if this PR adds/updates a Wall app)
make generate app APP="..." LINK="..." CREATOR="..." PLATFORM="..."(or manually editeddocs/wall-of-apps.json+ ranmake update-wall-of-apps)docs/wall-of-apps.jsonREADME.mdEntry template:
Common Apple labels:
iOS,macOS,watchOS,tvOS,visionOS.🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.