fix: reject unsafe package metadata paths - #1789
Draft
sapunyangkut wants to merge 1 commit into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
imageshould not pass validation #1591Summary
imageas well as the equivalentpathfields in contributors, licenses, and sourcesRoot cause
Package.metadata_validate()checked unsafe resource schema paths in untrusted mode, but it did not apply equivalent checks to package-level metadata paths. As a result, local absolute or parent-relative paths and unsupported schemes could pass validation. A malformed URL could also escape validation by raisingValueErrorfromurlparse().Validation
python -m pytest frictionless/package/__spec__/test_security.py -q— 122 passed, 2 skippedpython -m ruff check frictionless/package/package.py frictionless/package/__spec__/test_security.pypython -m ruff format --check frictionless/package/package.py frictionless/package/__spec__/test_security.pygit diff --checkAn additional run of the full
frictionless/package/__spec__directory was attempted, but it exceeded a 120-second local limit without reporting an assertion failure. The focused 124-case security module completed successfully.AI disclosure
This Draft PR was prepared and validated by an automated AI coding agent. The agent identified the root cause, produced the patch and tests, ran the checks listed above, and opened this Draft PR. It has not yet received human or maintainer review.