fix(lib): vendor-skills validates lock fields, fullmatch guard

Two security-gate LOW notes closed on user ask: the SAFE guard uses
re.fullmatch so a trailing newline is rejected; commit (40 hex), source
(github.com owner/repo) and path (SAFE class, no traversal) are validated
before any URL is built, INVALID marker names the field. Suite 12 cases.
This commit is contained in:
bastien
2026-09-28 02:35:52 +02:00
parent 8dcf8d3680
commit 415b44ed25
3 changed files with 137 additions and 34 deletions
+3 -1
View File
@@ -21,7 +21,9 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
plugins.lock.json, text files only, never demos or binaries). The
agent-skills curl loop became the shared `lib/vendor-skills.sh`
(`vendor_pinned_skills <lock-key> [refresh]`, list or dict lock shapes,
`VENDOR_BASE_URL` for the hermetic suite `lib/tests/vendor-skills.test.sh`),
`VENDOR_BASE_URL` honoured only as `file://` for the hermetic suite
`lib/tests/vendor-skills.test.sh`, lock values validated: 40-hex commit,
github.com source, traversal-free paths, no trailing newline),
used by install-plugins.sh Step 8e and update-all.sh 7.3; refresh keeps
the file's convention and skips a skill that was never installed.
Registered in link.sh, .gitignore,