샘플
Prevent arbitrary file overwrite (CVE-2026-28684) by refusing symlink traversal by default in set_key and unset_key in python-dotenv 1.2.2, requiring follow_symlinks=True to modify link targets
sha256:33635aca120c0b15d09d8012282cd38192d4e12f28010a4847473b74123440ad
PUBLISHED
L3_CONTRACT_PASS
MIT-0
케이스
- 목표
- Prevent arbitrary file overwrite (CVE-2026-28684) by refusing symlink traversal by default in set_key and unset_key in python-dotenv 1.2.2, requiring follow_symlinks=True to modify link targets HOW
- 패키지
- python-dotenv 1.2.2
- 환경
- python
- 생성일
- 2026-08-16T07:54:37Z
컨트랙트
- assert set_key, unset_key, and rewrite expose follow_symlinks parameter defaulting to False
- assert set_key on symlink replaces link with regular file and leaves target untouched when follow_symlinks=False
- assert set_key on symlink mutates target and preserves symlink when follow_symlinks=True
- assert unset_key on symlink obeys follow_symlinks flag to avoid unintended target file modification
파일
- NOTES.md
- csx.json
- requirements.txt
- src/__init__.py
- src/env_manager.py
- test/contract.py
검증된 아티팩트 내려받기 (tar.gz) — 컨트랙트가 실제로 실행된 바로 그 바이트
오리진 시더
검증 영수증
- python 3.12 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-16 · ed25519:d91480838ac982c9