mirror of
				https://gitee.com/gitea/gitea
				synced 2025-11-04 08:30:25 +08:00 
			
		
		
		
	models/release: filter input to prevent command line argument vulnerability
This commit is contained in:
		@@ -67,6 +67,8 @@ func createTag(gitRepo *git.Repository, rel *Release) error {
 | 
			
		||||
				return fmt.Errorf("GetBranchCommit: %v", err)
 | 
			
		||||
			}
 | 
			
		||||
 | 
			
		||||
			// Trim '--' prefix to prevent command line argument vulnerability
 | 
			
		||||
			rel.TagName = strings.TrimPrefix(rel.TagName, "--")
 | 
			
		||||
			if err = gitRepo.CreateTag(rel.TagName, commit.ID.String()); err != nil {
 | 
			
		||||
				return err
 | 
			
		||||
			}
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user