Skip to content

Commit 8f52674

Browse files
committed
Disallow / in key names
Signed-off-by: Nghia Tran <nghia@chainguard.dev>
1 parent ec48e30 commit 8f52674

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

pkg/apk/apk/index.go

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -343,6 +343,12 @@ func parseRepositoryIndex(ctx context.Context, u string, keys map[string][]byte,
343343
if len(keys) == 0 {
344344
return nil, fmt.Errorf("no keys provided to verify signature")
345345
}
346+
// check that they key name aren't paths or URLs
347+
for keyName := range keys {
348+
if strings.Contains(keyName, "/") {
349+
return nil, fmt.Errorf("invalid keyname %q", keyName)
350+
}
351+
}
346352
buf := bytes.NewReader(b)
347353
gzipReader, err := gzip.NewReader(buf)
348354
if err != nil {

0 commit comments

Comments
 (0)