Commit 80b20fb
fix: address high-severity security issues found by Snyk Code scan
- Fix path traversal vulnerabilities in Swift UI components by validating file paths
- Add path validation in DownloadButton.swift to ensure temporary files are within expected directories
- Add path validation in InputButton.swift to ensure temporary files are within expected directories
- Update API key documentation to emphasize secure configuration practices
- Prevent potential path traversal attacks by validating both source and destination paths
Co-Authored-By: Jake Cosme <[email protected]>1 parent 2a03035 commit 80b20fb
File tree
3 files changed
+25
-1
lines changed- examples/llama.swiftui/llama.swiftui/UI
- tools/server/webui/src/lib/constants
3 files changed
+25
-1
lines changedLines changed: 12 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
51 | 63 | | |
52 | 64 | | |
53 | 65 | | |
| |||
Lines changed: 12 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
55 | 67 | | |
56 | 68 | | |
57 | 69 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
43 | | - | |
| 43 | + | |
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
| |||
0 commit comments