refactor: use shutil.which for secure command check#1922
Open
RinZ27 wants to merge 1 commit intoFoundationAgents:mainfrom
Open
refactor: use shutil.which for secure command check#1922RinZ27 wants to merge 1 commit intoFoundationAgents:mainfrom
RinZ27 wants to merge 1 commit intoFoundationAgents:mainfrom
Conversation
e18b188 to
4d24900
Compare
4d24900 to
b35cf66
Compare
b35cf66 to
d476dce
Compare
d476dce to
760c084
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaced insecure
os.systemcall withshutil.whichincheck_cmd_existsfunction.Context
The original implementation constructed a shell command by concatenating the input
commandstring:This pattern is vulnerable to command injection if
commandcomes from an untrusted source. Whilecheck_cmd_existsis currently used internally, it is a public utility function exposed by the library, making it a potential security risk if misused by consumers of the library.Fix
Refactored to use
shutil.which(), which is the standard, secure, and cross-platform way to check for executables in Python. It avoids shell execution entirely.Benefits