Skip to content
This repository has been archived by the owner on Jun 22, 2024. It is now read-only.

Banned some configs from workspace settings

Latest
Compare
Choose a tag to compare
@vknabel vknabel released this 15 Mar 18:44
· 40 commits to master since this release

CVE-2021-28792: Fixes vulnerability which allowed malicous workspaces to execute code when opened by providing. Now the vulnerable configs cannot be overrided in workspaces anymore:
sourcekit-lsp.serverPath, swift.languageServerPath, swift.path.sourcekite, swift.path.sourcekiteDockerMode, swift.path.swift_driver_bin, swift.path.shell. Reported by @Ry0taK.