Skip to content

Fix Golang Zip Slip Vulnerability - #39638

Merged
jrmccluskey merged 1 commit into
apache:masterfrom
jrmccluskey:zipZapZop
Aug 18, 2026
Merged

Fix Golang Zip Slip Vulnerability#39638
jrmccluskey merged 1 commit into
apache:masterfrom
jrmccluskey:zipZapZop

Conversation

@jrmccluskey

Copy link
Copy Markdown
Contributor

Validates paths in the Go SDK's automated expansion service startup to prevent directory traversal attacks.

Fixes https://github.com/apache/beam/security/code-scanning/72


Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:

  • Mention the appropriate issue in your description (for example: addresses #123), if applicable. This will automatically add a link to the pull request in the issue. If you would like the issue to automatically close on merging the pull request, comment fixes #<ISSUE NUMBER> instead.
  • Update CHANGES.md with noteworthy changes.
  • If this contribution is large, please file an Apache Individual Contributor License Agreement.

See the Contributor Guide for more tips on how to make review process smoother.

To check the build health, please visit https://github.com/apache/beam/blob/master/.test-infra/BUILD_STATUS.md

GitHub Actions Tests Status (on master branch)

Build python source distribution and wheels
Python tests
Java tests
Go tests

See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.

@jrmccluskey

Copy link
Copy Markdown
ContributorAuthor

R: @shunping

@github-actions

Copy link
Copy Markdown
Contributor

Stopping reviewer notifications for this pull request: review requested by someone other than the bot, ceding control. If you'd like to restart, comment assign set of reviewers

@bvolpatobvolpato left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jrmccluskey
jrmccluskey merged commit c08f2a8 into apache:masterAug 18, 2026
9 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jrmccluskey@bvolpato