When running in CI, a malicious actor could open a PR with a requirements.txt file that links to other secret files that are formatted like requirements.txt (and match valid versions, so quite niche), and force osv-scanner to print out the contents (e.g. as a vulnerability report).
We should prevent this in two ways:
- Defaulting to not setting ScanRoot to
/ (This is a breaking change)
- Adding an extra flag to allow users to manually set the scan root.
Lodging this as a task for V3.
See google/osv-scalibr#2323 for context.
When running in CI, a malicious actor could open a PR with a requirements.txt file that links to other secret files that are formatted like requirements.txt (and match valid versions, so quite niche), and force osv-scanner to print out the contents (e.g. as a vulnerability report).
We should prevent this in two ways:
/(This is a breaking change)Lodging this as a task for V3.
See google/osv-scalibr#2323 for context.