Skip to content

Conversation

@anim001k
Copy link
Contributor

@anim001k anim001k commented Dec 7, 2025

Add bounded gunzip helper for npm installer to prevent unbounded decompression. Apply max-size check when unpacking downloaded tarball before writing binary.

@zerosnacks
Copy link
Member

Considering we control what artifacts are downloaded this fix is not required

@zerosnacks zerosnacks closed this Dec 8, 2025
@github-project-automation github-project-automation bot moved this to Done in Foundry Dec 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants