+
Skip to content

feat: improve bot-conditions checks #905

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 7 commits into from
Jun 6, 2025
Merged

Conversation

woodruffw
Copy link
Member

@woodruffw woodruffw commented Jun 6, 2025

WIP.

https://boostsecurity.io/blog/weaponizing-dependabot-pwn-request-at-its-finest made me realize that there were a couple of contexts we weren't checking for properly.

Separately, this also switches bot-conditions to use our context pattern APIs (so that we handle more varieties of contexts, like index-style contexts) and begins the work to ensure we handle numeric actor ID checks as well.

Signed-off-by: William Woodruff <william@yossarian.net>
@woodruffw woodruffw self-assigned this Jun 6, 2025
@woodruffw woodruffw added the enhancement New feature or request label Jun 6, 2025
woodruffw added 6 commits June 6, 2025 16:40
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
Signed-off-by: William Woodruff <william@yossarian.net>
@woodruffw woodruffw merged commit ad7b6d0 into main Jun 6, 2025
8 checks passed
@woodruffw woodruffw deleted the ww/bot-conditions-improvements branch June 6, 2025 21:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载