fix(security): replace exec with execFile for git commands - #162
Draft
prathamesh04 wants to merge 2 commits into
Draft
fix(security): replace exec with execFile for git commands#162prathamesh04 wants to merge 2 commits into
prathamesh04 wants to merge 2 commits into
Conversation
Fixes infinite loop in assignColorToWorker when all 16 ANSI colors are allocated. Previously, the do...while loop would spin forever looking for an unassigned color, blocking the Node.js event loop and hanging the server at 17+ concurrent deployments. Changes: - Replace random retry with deterministic round-robin index - Remove assignedColorCodes tracking map (no longer needed) - Remove unused AssignedColorCodesType interface - Remove stale TODO comments Colors cycle safely when more than 16 deployments are active. Fixes metacall#116
Repository endpoints were using shell-based exec for git commands, allowing command injection through crafted URLs or branch names. Even with input validation, the shell remains a security risk. Changes: - Add execFile utility as safe alternative to exec - Replace all exec calls with execFile using argument arrays - No shell involved, so metacharacters in arguments are harmless - Keep existing URL/branch validators for additional defense Fixes metacall#111
Contributor
Author
Member
|
You have mixed two commits in the same one, the previous PR and the current one, if you push only the execFile change, I will merge it. @prathamesh04 |
viferga
marked this pull request as draft
August 3, 2026 15:02
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Repository endpoints were using shell-based
execfor git commands, allowing command injection through crafted URLs or branch names. Even with input validation, the shell remains a security risk.Fixes #111
Changes
execFileutility as safe alternative toexecexeccalls withexecFileusing argument arraysSecurity Impact
This is a critical security fix that prevents:
Checklist
npm run build)npm run lint)