Skip to content

src,permission: do not grant cwd read access without entrypoint - #66645

Open
RafaelGSS wants to merge 2 commits into
nodejs:mainfrom
RafaelGSS:src-permission-do-not-grant-cwd-read-access-withou
Open

RafaelGSS wants to merge 2 commits into
nodejs:mainfrom
RafaelGSS:src-permission-do-not-grant-cwd-read-access-withou

Conversation

@RafaelGSS

Copy link
Copy Markdown
Member

src,permission: do not grant cwd read access without entrypoint

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/security-wg

@nodejs-github-bot nodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. labels Oct 10, 2026
@codecov

codecov Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 90.48%. Comparing base (dd9777b) to head (f18fd0a).
⚠️ Report is 42 commits behind head on main.

Files with missing lines Patch % Lines
src/env.cc 0.00% 0 Missing and 1 partial ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main   #66645      +/-   ##
==========================================
- Coverage   92.78%   90.48%   -2.31%     
==========================================
  Files         422      791     +369     
  Lines      193692   277097   +83405     
  Branches    29881    53274   +23393     
==========================================
+ Hits       179714   250721   +71007     
- Misses      13650    16775    +3125     
- Partials      328     9601    +9273     
Files with missing lines Coverage Δ
src/env.cc 84.16% <0.00%> (ø)

... and 509 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS RafaelGSS added author ready PRs with CI started, the required approvals, and no outstanding review comments. permission Issues and PRs related to the Permission Model. request-ci Add this label to start a Jenkins CI on a PR. Only starts once the PR has an approving review. labels Oct 11, 2026
@github-actions github-actions Bot removed the request-ci Add this label to start a Jenkins CI on a PR. Only starts once the PR has an approving review. label Oct 11, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author ready PRs with CI started, the required approvals, and no outstanding review comments. c++ Issues and PRs that require attention from people who are familiar with C++. needs-ci PRs that need a full CI run. permission Issues and PRs related to the Permission Model.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants