Skip to content

Security/script assessment dev#9

Open
benhunter wants to merge 2 commits into
masterfrom
security/script-assessment-dev
Open

Security/script assessment dev#9
benhunter wants to merge 2 commits into
masterfrom
security/script-assessment-dev

Conversation

@benhunter

Copy link
Copy Markdown
Owner

No description provided.

benhunter added 2 commits June 8, 2026 12:12
Introduce a Security validation GitHub Actions workflow and tests, add a .gitignore for __pycache__, and harden many scripts across the repo. Changes include: atomic, ACL-restricted state handling and CSV safety for Monitor-ADGroupChanges.ps1; safer Watch-Command.ps1 using a scriptblock param; stricter shell scripts (set -Eeuo pipefail, input validation, umask, safer tmp files) and retire/disable unsafe installers (example-deploy.sh, gitlab-clone-group.sh). Improve utilities (docker-debug-container, expand_root_volume, gcp-subnets-enable-flow-logs, git-delete-merged-branches, github-latest-tag, gitlab image/tag checks), tighten container invocation for TeX PDF generation (digest-pinned image, reduced privileges), JS/HTML DOM updates in file-manager, and add tests/test_security_regressions.py. Overall focus: automated parsing/testing, input validation, least-privilege execution, safer file handling, and retiring unsafe prototypes.
@benhunter

Copy link
Copy Markdown
Owner Author

@copilot please review

Copilot AI commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

@copilot please review

I reviewed the two commits and re-ran the validation checks (unit tests, Bash/Python/JS parsing, and ShellCheck). Everything passes, and I didn’t find any additional changes needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants