Skip to content

Update from code changes: document archive extraction limits - #1157

Merged
Doezer merged 1 commit into
mainfrom
mintlify/0d70a896
Oct 6, 2026
Merged

Doezer merged 1 commit into
mainfrom
mintlify/0d70a896

Conversation

@mintlify

@mintlify mintlify Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Documents the archive preflight checks and the two new optional limit env vars added in #1149.

Changes

  • SECRETS.md §1: added ARCHIVE_MAX_ENTRIES (default 50,000) and ARCHIVE_MAX_EXPANDED_BYTES (default 250 GiB) rows, plus an "Archive extraction limits" subsection. It lists every refusal reason with its error message and shows how to raise the limits.
  • SECURITY_ASSESSMENT.md: new risk-register row for untrusted archive extraction (decompression bombs, path traversal, links).
  • THREAT_MODEL.md §6: added archive extraction to the mitigations index.

Context

Source: #1149 (archive bounds portion only).

@mintlify

mintlify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor Author

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
questarr 🟢 Ready View Preview Oct 6, 2026, 7:10 AM

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: dd606bfa-586a-43df-830f-6a459e4a4b6a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mintlify
mintlify Bot requested a review from Doezer October 6, 2026 07:10
@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@Doezer

Doezer commented Oct 6, 2026

Copy link
Copy Markdown
Owner

wshm · Automated triage by AI

📊 Automated PR Analysis

📝 Type docs
🟢 Risk low

Summary

This PR documents newly added archive extraction preflight checks and limits (ARCHIVE_MAX_ENTRIES, ARCHIVE_MAX_EXPANDED_BYTES) introduced in a related PR, updating SECRETS.md, SECURITY_ASSESSMENT.md, and THREAT_MODEL.md accordingly. It adds a risk-register entry and explains error messages and how to adjust the limits via environment variables.

Review Checklist

  • Tests present
  • Breaking change
  • Docs updated

Analyzed automatically by wshm · This is an automated analysis, not a human review.

@Doezer
Doezer merged commit 52de3be into main Oct 6, 2026
6 checks passed
@Doezer
Doezer deleted the mintlify/0d70a896 branch October 6, 2026 11:01

This branch was successfully deployed

1 active deployment
staging - docs — af12f025 Deployed Oct 6, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant