Skip to content

Commit

Permalink
docs(CHANGES): Note vulnerability fix
Browse files Browse the repository at this point in the history
  • Loading branch information
tony committed Mar 12, 2022
1 parent 3f4e93e commit 66640ae
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions CHANGES
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,12 @@

- _Add your latest changes from PRs here_

### Potential command injection via mercurial URLs

- By setting a mercurial URL with an alias it is possible to execute arbitrary shell commands via
`.obtain()` or in the case of uncloned destinations, `.update_repo()`. (#306, credit: Alessio
Della Libera)

### Development

- Run pyupgrade formatting (#305)
Expand Down

0 comments on commit 66640ae

Please sign in to comment.