Require explicit opt-in for filesystem diffs - #2217

Merged
Byron merged 1 commit into
mainfrom
fix-advisory
Aug 17, 2026
Merged

Require explicit opt-in for filesystem diffs#2217
Byron merged 1 commit into
mainfrom
fix-advisory

Conversation

@Byron

@ByronByron commented Aug 17, 2026

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-5.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Advisory

GHSA-whh4-5q6c-9v3x

GHSA-whh4-5q6c-9v3x reports a repository-boundary bypass in the high-level diff API. This change requires callers to explicitly opt in before diff paths may use filesystem-wide semantics. Reproduction mechanics are intentionally omitted while the advisory is unpublished.

Advisory summary

  • Severity: medium
  • Package: GitPython (pip)
  • Affected range: = 3.1.59
  • Patched versions: none published
  • CVE: none assigned

Changes

  • Classify --no-index as an unsafe diff option.
  • Cover keyword and raw-option spellings through commit and index APIs.
  • Clarify the existing explicit opt-in documentation.

Validation

  • Focused diff security tests: 2 passed.
  • Complete test/test_diff.py: 25 passed, 1 unrelated local-environment failure in staged conflict reporting.
  • Ruff check and format checks passed.
  • git diff --check passed.
  • Git baseline: Git 2.50.1 documents filesystem operand behavior in Documentation/git-diff.adoc and implements it in builtin/diff.c.
  • Post-commit Codex review was attempted once for 14200584 but the CLI usage allowance was exhausted before review began.

CopilotAI lite review requested due to automatic review settings August 17, 2026 04:15

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens GitPython’s high-level diff APIs against repository-boundary bypass by requiring explicit caller opt-in before enabling filesystem-wide diff semantics (--no-index).

Changes:

  • Mark --no-index as an unsafe diff option (requires allow_unsafe_options=True).
  • Add regression tests ensuring both keyword (no_index=True) and raw-option ("--no-index") spellings are rejected by default.
  • Update Diffable.diff documentation to include --no-index in the unsafe-options description.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
test/test_diff.pyAdds tests that --no-index/no_index are blocked unless explicitly allowed.
git/repo/base.pyAdds --no-index to the repo’s unsafe diff option allowlist/denylist used by high-level diff APIs.
git/diff.pyUpdates the allow_unsafe_options docstring to document --no-index as unsafe.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadgit/repo/base.py Outdated
CopilotAI review requested due to automatic review settings August 17, 2026 04:34

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

<!-- agent -->
Treat --no-index as an unsafe diff option because it changes path operands
from repository pathspecs to arbitrary filesystem paths. This addresses
GHSA-whh4-5q6c-9v3x without exposing advisory reproduction details.
Assisted-by: GPT 5.6
Co-authored-by: GPT 5.6 <codex@openai.com>
CopilotAI review requested due to automatic review settings August 17, 2026 04:47

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

@Byron
Byron merged commit d160fb4 into mainAug 17, 2026
54 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Byron
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Require explicit opt-in for filesystem diffs - #2217

Merged
Byron merged 1 commit into
mainfrom
fix-advisory
Aug 17, 2026
Merged

Require explicit opt-in for filesystem diffs#2217
Byron merged 1 commit into
mainfrom
fix-advisory

Conversation

@Byron

@ByronByron commented Aug 17, 2026

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-5.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Advisory

GHSA-whh4-5q6c-9v3x

GHSA-whh4-5q6c-9v3x reports a repository-boundary bypass in the high-level diff API. This change requires callers to explicitly opt in before diff paths may use filesystem-wide semantics. Reproduction mechanics are intentionally omitted while the advisory is unpublished.

Advisory summary

  • Severity: medium
  • Package: GitPython (pip)
  • Affected range: = 3.1.59
  • Patched versions: none published
  • CVE: none assigned

Changes

  • Classify --no-index as an unsafe diff option.
  • Cover keyword and raw-option spellings through commit and index APIs.
  • Clarify the existing explicit opt-in documentation.

Validation

  • Focused diff security tests: 2 passed.
  • Complete test/test_diff.py: 25 passed, 1 unrelated local-environment failure in staged conflict reporting.
  • Ruff check and format checks passed.
  • git diff --check passed.
  • Git baseline: Git 2.50.1 documents filesystem operand behavior in Documentation/git-diff.adoc and implements it in builtin/diff.c.
  • Post-commit Codex review was attempted once for 14200584 but the CLI usage allowance was exhausted before review began.

CopilotAI lite review requested due to automatic review settings August 17, 2026 04:15

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens GitPython’s high-level diff APIs against repository-boundary bypass by requiring explicit caller opt-in before enabling filesystem-wide diff semantics (--no-index).

Changes:

  • Mark --no-index as an unsafe diff option (requires allow_unsafe_options=True).
  • Add regression tests ensuring both keyword (no_index=True) and raw-option ("--no-index") spellings are rejected by default.
  • Update Diffable.diff documentation to include --no-index in the unsafe-options description.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
test/test_diff.pyAdds tests that --no-index/no_index are blocked unless explicitly allowed.
git/repo/base.pyAdds --no-index to the repo’s unsafe diff option allowlist/denylist used by high-level diff APIs.
git/diff.pyUpdates the allow_unsafe_options docstring to document --no-index as unsafe.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadgit/repo/base.py Outdated
CopilotAI review requested due to automatic review settings August 17, 2026 04:34

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

<!-- agent -->
Treat --no-index as an unsafe diff option because it changes path operands
from repository pathspecs to arbitrary filesystem paths. This addresses
GHSA-whh4-5q6c-9v3x without exposing advisory reproduction details.
Assisted-by: GPT 5.6
Co-authored-by: GPT 5.6 <codex@openai.com>
CopilotAI review requested due to automatic review settings August 17, 2026 04:47

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

@Byron
Byron merged commit d160fb4 into mainAug 17, 2026
54 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Byron
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Require explicit opt-in for filesystem diffs - #2217

Merged
Byron merged 1 commit into
mainfrom
fix-advisory
Aug 17, 2026
Merged

Require explicit opt-in for filesystem diffs#2217
Byron merged 1 commit into
mainfrom
fix-advisory

Conversation

@Byron

@ByronByron commented Aug 17, 2026

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-5.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Advisory

GHSA-whh4-5q6c-9v3x

GHSA-whh4-5q6c-9v3x reports a repository-boundary bypass in the high-level diff API. This change requires callers to explicitly opt in before diff paths may use filesystem-wide semantics. Reproduction mechanics are intentionally omitted while the advisory is unpublished.

Advisory summary

  • Severity: medium
  • Package: GitPython (pip)
  • Affected range: = 3.1.59
  • Patched versions: none published
  • CVE: none assigned

Changes

  • Classify --no-index as an unsafe diff option.
  • Cover keyword and raw-option spellings through commit and index APIs.
  • Clarify the existing explicit opt-in documentation.

Validation

  • Focused diff security tests: 2 passed.
  • Complete test/test_diff.py: 25 passed, 1 unrelated local-environment failure in staged conflict reporting.
  • Ruff check and format checks passed.
  • git diff --check passed.
  • Git baseline: Git 2.50.1 documents filesystem operand behavior in Documentation/git-diff.adoc and implements it in builtin/diff.c.
  • Post-commit Codex review was attempted once for 14200584 but the CLI usage allowance was exhausted before review began.

CopilotAI lite review requested due to automatic review settings August 17, 2026 04:15

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens GitPython’s high-level diff APIs against repository-boundary bypass by requiring explicit caller opt-in before enabling filesystem-wide diff semantics (--no-index).

Changes:

  • Mark --no-index as an unsafe diff option (requires allow_unsafe_options=True).
  • Add regression tests ensuring both keyword (no_index=True) and raw-option ("--no-index") spellings are rejected by default.
  • Update Diffable.diff documentation to include --no-index in the unsafe-options description.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
test/test_diff.pyAdds tests that --no-index/no_index are blocked unless explicitly allowed.
git/repo/base.pyAdds --no-index to the repo’s unsafe diff option allowlist/denylist used by high-level diff APIs.
git/diff.pyUpdates the allow_unsafe_options docstring to document --no-index as unsafe.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadgit/repo/base.py Outdated
CopilotAI review requested due to automatic review settings August 17, 2026 04:34

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

<!-- agent -->
Treat --no-index as an unsafe diff option because it changes path operands
from repository pathspecs to arbitrary filesystem paths. This addresses
GHSA-whh4-5q6c-9v3x without exposing advisory reproduction details.
Assisted-by: GPT 5.6
Co-authored-by: GPT 5.6 <codex@openai.com>
CopilotAI review requested due to automatic review settings August 17, 2026 04:47

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

@Byron
Byron merged commit d160fb4 into mainAug 17, 2026
54 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Byron
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Require explicit opt-in for filesystem diffs - #2217

Merged
Byron merged 1 commit into
mainfrom
fix-advisory
Aug 17, 2026
Merged

Require explicit opt-in for filesystem diffs#2217
Byron merged 1 commit into
mainfrom
fix-advisory

Conversation

@Byron

@ByronByron commented Aug 17, 2026

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-5.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Advisory

GHSA-whh4-5q6c-9v3x

GHSA-whh4-5q6c-9v3x reports a repository-boundary bypass in the high-level diff API. This change requires callers to explicitly opt in before diff paths may use filesystem-wide semantics. Reproduction mechanics are intentionally omitted while the advisory is unpublished.

Advisory summary

  • Severity: medium
  • Package: GitPython (pip)
  • Affected range: = 3.1.59
  • Patched versions: none published
  • CVE: none assigned

Changes

  • Classify --no-index as an unsafe diff option.
  • Cover keyword and raw-option spellings through commit and index APIs.
  • Clarify the existing explicit opt-in documentation.

Validation

  • Focused diff security tests: 2 passed.
  • Complete test/test_diff.py: 25 passed, 1 unrelated local-environment failure in staged conflict reporting.
  • Ruff check and format checks passed.
  • git diff --check passed.
  • Git baseline: Git 2.50.1 documents filesystem operand behavior in Documentation/git-diff.adoc and implements it in builtin/diff.c.
  • Post-commit Codex review was attempted once for 14200584 but the CLI usage allowance was exhausted before review began.

CopilotAI lite review requested due to automatic review settings August 17, 2026 04:15

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens GitPython’s high-level diff APIs against repository-boundary bypass by requiring explicit caller opt-in before enabling filesystem-wide diff semantics (--no-index).

Changes:

  • Mark --no-index as an unsafe diff option (requires allow_unsafe_options=True).
  • Add regression tests ensuring both keyword (no_index=True) and raw-option ("--no-index") spellings are rejected by default.
  • Update Diffable.diff documentation to include --no-index in the unsafe-options description.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
test/test_diff.pyAdds tests that --no-index/no_index are blocked unless explicitly allowed.
git/repo/base.pyAdds --no-index to the repo’s unsafe diff option allowlist/denylist used by high-level diff APIs.
git/diff.pyUpdates the allow_unsafe_options docstring to document --no-index as unsafe.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadgit/repo/base.py Outdated
CopilotAI review requested due to automatic review settings August 17, 2026 04:34

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

<!-- agent -->
Treat --no-index as an unsafe diff option because it changes path operands
from repository pathspecs to arbitrary filesystem paths. This addresses
GHSA-whh4-5q6c-9v3x without exposing advisory reproduction details.
Assisted-by: GPT 5.6
Co-authored-by: GPT 5.6 <codex@openai.com>
CopilotAI review requested due to automatic review settings August 17, 2026 04:47

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

@Byron
Byron merged commit d160fb4 into mainAug 17, 2026
54 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Byron
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Require explicit opt-in for filesystem diffs - #2217

Merged
Byron merged 1 commit into
mainfrom
fix-advisory
Aug 17, 2026
Merged

Require explicit opt-in for filesystem diffs#2217
Byron merged 1 commit into
mainfrom
fix-advisory

Conversation

@Byron

@ByronByron commented Aug 17, 2026

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-5.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Advisory

GHSA-whh4-5q6c-9v3x

GHSA-whh4-5q6c-9v3x reports a repository-boundary bypass in the high-level diff API. This change requires callers to explicitly opt in before diff paths may use filesystem-wide semantics. Reproduction mechanics are intentionally omitted while the advisory is unpublished.

Advisory summary

  • Severity: medium
  • Package: GitPython (pip)
  • Affected range: = 3.1.59
  • Patched versions: none published
  • CVE: none assigned

Changes

  • Classify --no-index as an unsafe diff option.
  • Cover keyword and raw-option spellings through commit and index APIs.
  • Clarify the existing explicit opt-in documentation.

Validation

  • Focused diff security tests: 2 passed.
  • Complete test/test_diff.py: 25 passed, 1 unrelated local-environment failure in staged conflict reporting.
  • Ruff check and format checks passed.
  • git diff --check passed.
  • Git baseline: Git 2.50.1 documents filesystem operand behavior in Documentation/git-diff.adoc and implements it in builtin/diff.c.
  • Post-commit Codex review was attempted once for 14200584 but the CLI usage allowance was exhausted before review began.

CopilotAI lite review requested due to automatic review settings August 17, 2026 04:15

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens GitPython’s high-level diff APIs against repository-boundary bypass by requiring explicit caller opt-in before enabling filesystem-wide diff semantics (--no-index).

Changes:

  • Mark --no-index as an unsafe diff option (requires allow_unsafe_options=True).
  • Add regression tests ensuring both keyword (no_index=True) and raw-option ("--no-index") spellings are rejected by default.
  • Update Diffable.diff documentation to include --no-index in the unsafe-options description.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
test/test_diff.pyAdds tests that --no-index/no_index are blocked unless explicitly allowed.
git/repo/base.pyAdds --no-index to the repo’s unsafe diff option allowlist/denylist used by high-level diff APIs.
git/diff.pyUpdates the allow_unsafe_options docstring to document --no-index as unsafe.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadgit/repo/base.py Outdated
CopilotAI review requested due to automatic review settings August 17, 2026 04:34

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

<!-- agent -->
Treat --no-index as an unsafe diff option because it changes path operands
from repository pathspecs to arbitrary filesystem paths. This addresses
GHSA-whh4-5q6c-9v3x without exposing advisory reproduction details.
Assisted-by: GPT 5.6
Co-authored-by: GPT 5.6 <codex@openai.com>
CopilotAI review requested due to automatic review settings August 17, 2026 04:47

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

@Byron
Byron merged commit d160fb4 into mainAug 17, 2026
54 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Byron
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Require explicit opt-in for filesystem diffs - #2217

Merged
Byron merged 1 commit into
mainfrom
fix-advisory
Aug 17, 2026
Merged

Require explicit opt-in for filesystem diffs#2217
Byron merged 1 commit into
mainfrom
fix-advisory

Conversation

@Byron

@ByronByron commented Aug 17, 2026

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-5.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Advisory

GHSA-whh4-5q6c-9v3x

GHSA-whh4-5q6c-9v3x reports a repository-boundary bypass in the high-level diff API. This change requires callers to explicitly opt in before diff paths may use filesystem-wide semantics. Reproduction mechanics are intentionally omitted while the advisory is unpublished.

Advisory summary

  • Severity: medium
  • Package: GitPython (pip)
  • Affected range: = 3.1.59
  • Patched versions: none published
  • CVE: none assigned

Changes

  • Classify --no-index as an unsafe diff option.
  • Cover keyword and raw-option spellings through commit and index APIs.
  • Clarify the existing explicit opt-in documentation.

Validation

  • Focused diff security tests: 2 passed.
  • Complete test/test_diff.py: 25 passed, 1 unrelated local-environment failure in staged conflict reporting.
  • Ruff check and format checks passed.
  • git diff --check passed.
  • Git baseline: Git 2.50.1 documents filesystem operand behavior in Documentation/git-diff.adoc and implements it in builtin/diff.c.
  • Post-commit Codex review was attempted once for 14200584 but the CLI usage allowance was exhausted before review began.

CopilotAI lite review requested due to automatic review settings August 17, 2026 04:15

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens GitPython’s high-level diff APIs against repository-boundary bypass by requiring explicit caller opt-in before enabling filesystem-wide diff semantics (--no-index).

Changes:

  • Mark --no-index as an unsafe diff option (requires allow_unsafe_options=True).
  • Add regression tests ensuring both keyword (no_index=True) and raw-option ("--no-index") spellings are rejected by default.
  • Update Diffable.diff documentation to include --no-index in the unsafe-options description.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
test/test_diff.pyAdds tests that --no-index/no_index are blocked unless explicitly allowed.
git/repo/base.pyAdds --no-index to the repo’s unsafe diff option allowlist/denylist used by high-level diff APIs.
git/diff.pyUpdates the allow_unsafe_options docstring to document --no-index as unsafe.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadgit/repo/base.py Outdated
CopilotAI review requested due to automatic review settings August 17, 2026 04:34

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

<!-- agent -->
Treat --no-index as an unsafe diff option because it changes path operands
from repository pathspecs to arbitrary filesystem paths. This addresses
GHSA-whh4-5q6c-9v3x without exposing advisory reproduction details.
Assisted-by: GPT 5.6
Co-authored-by: GPT 5.6 <codex@openai.com>
CopilotAI review requested due to automatic review settings August 17, 2026 04:47

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

@Byron
Byron merged commit d160fb4 into mainAug 17, 2026
54 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Byron
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Require explicit opt-in for filesystem diffs - #2217

Merged
Byron merged 1 commit into
mainfrom
fix-advisory
Aug 17, 2026
Merged

Require explicit opt-in for filesystem diffs#2217
Byron merged 1 commit into
mainfrom
fix-advisory

Conversation

@Byron

@ByronByron commented Aug 17, 2026

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-5.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Advisory

GHSA-whh4-5q6c-9v3x

GHSA-whh4-5q6c-9v3x reports a repository-boundary bypass in the high-level diff API. This change requires callers to explicitly opt in before diff paths may use filesystem-wide semantics. Reproduction mechanics are intentionally omitted while the advisory is unpublished.

Advisory summary

  • Severity: medium
  • Package: GitPython (pip)
  • Affected range: = 3.1.59
  • Patched versions: none published
  • CVE: none assigned

Changes

  • Classify --no-index as an unsafe diff option.
  • Cover keyword and raw-option spellings through commit and index APIs.
  • Clarify the existing explicit opt-in documentation.

Validation

  • Focused diff security tests: 2 passed.
  • Complete test/test_diff.py: 25 passed, 1 unrelated local-environment failure in staged conflict reporting.
  • Ruff check and format checks passed.
  • git diff --check passed.
  • Git baseline: Git 2.50.1 documents filesystem operand behavior in Documentation/git-diff.adoc and implements it in builtin/diff.c.
  • Post-commit Codex review was attempted once for 14200584 but the CLI usage allowance was exhausted before review began.

CopilotAI lite review requested due to automatic review settings August 17, 2026 04:15

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens GitPython’s high-level diff APIs against repository-boundary bypass by requiring explicit caller opt-in before enabling filesystem-wide diff semantics (--no-index).

Changes:

  • Mark --no-index as an unsafe diff option (requires allow_unsafe_options=True).
  • Add regression tests ensuring both keyword (no_index=True) and raw-option ("--no-index") spellings are rejected by default.
  • Update Diffable.diff documentation to include --no-index in the unsafe-options description.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
test/test_diff.pyAdds tests that --no-index/no_index are blocked unless explicitly allowed.
git/repo/base.pyAdds --no-index to the repo’s unsafe diff option allowlist/denylist used by high-level diff APIs.
git/diff.pyUpdates the allow_unsafe_options docstring to document --no-index as unsafe.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadgit/repo/base.py Outdated
CopilotAI review requested due to automatic review settings August 17, 2026 04:34

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

<!-- agent -->
Treat --no-index as an unsafe diff option because it changes path operands
from repository pathspecs to arbitrary filesystem paths. This addresses
GHSA-whh4-5q6c-9v3x without exposing advisory reproduction details.
Assisted-by: GPT 5.6
Co-authored-by: GPT 5.6 <codex@openai.com>
CopilotAI review requested due to automatic review settings August 17, 2026 04:47

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

@Byron
Byron merged commit d160fb4 into mainAug 17, 2026
54 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Byron
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Require explicit opt-in for filesystem diffs - #2217

Merged
Byron merged 1 commit into
mainfrom
fix-advisory
Aug 17, 2026
Merged

Require explicit opt-in for filesystem diffs#2217
Byron merged 1 commit into
mainfrom
fix-advisory

Conversation

@Byron

@ByronByron commented Aug 17, 2026

Copy link
Copy Markdown
Member

Tasks

This section is for Byron only. Models continuing this PR must not add, remove, check, uncheck, rename, or reorder checkboxes here.

  • refackiew

Everything below this line was generated by Codex GPT-5.

Created by Codex on behalf of Byron. Byron will review before this is ready to merge.

Advisory

GHSA-whh4-5q6c-9v3x

GHSA-whh4-5q6c-9v3x reports a repository-boundary bypass in the high-level diff API. This change requires callers to explicitly opt in before diff paths may use filesystem-wide semantics. Reproduction mechanics are intentionally omitted while the advisory is unpublished.

Advisory summary

  • Severity: medium
  • Package: GitPython (pip)
  • Affected range: = 3.1.59
  • Patched versions: none published
  • CVE: none assigned

Changes

  • Classify --no-index as an unsafe diff option.
  • Cover keyword and raw-option spellings through commit and index APIs.
  • Clarify the existing explicit opt-in documentation.

Validation

  • Focused diff security tests: 2 passed.
  • Complete test/test_diff.py: 25 passed, 1 unrelated local-environment failure in staged conflict reporting.
  • Ruff check and format checks passed.
  • git diff --check passed.
  • Git baseline: Git 2.50.1 documents filesystem operand behavior in Documentation/git-diff.adoc and implements it in builtin/diff.c.
  • Post-commit Codex review was attempted once for 14200584 but the CLI usage allowance was exhausted before review began.

CopilotAI lite review requested due to automatic review settings August 17, 2026 04:15

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens GitPython’s high-level diff APIs against repository-boundary bypass by requiring explicit caller opt-in before enabling filesystem-wide diff semantics (--no-index).

Changes:

  • Mark --no-index as an unsafe diff option (requires allow_unsafe_options=True).
  • Add regression tests ensuring both keyword (no_index=True) and raw-option ("--no-index") spellings are rejected by default.
  • Update Diffable.diff documentation to include --no-index in the unsafe-options description.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
test/test_diff.pyAdds tests that --no-index/no_index are blocked unless explicitly allowed.
git/repo/base.pyAdds --no-index to the repo’s unsafe diff option allowlist/denylist used by high-level diff APIs.
git/diff.pyUpdates the allow_unsafe_options docstring to document --no-index as unsafe.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment threadgit/repo/base.py Outdated
CopilotAI review requested due to automatic review settings August 17, 2026 04:34

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

<!-- agent -->
Treat --no-index as an unsafe diff option because it changes path operands
from repository pathspecs to arbitrary filesystem paths. This addresses
GHSA-whh4-5q6c-9v3x without exposing advisory reproduction details.
Assisted-by: GPT 5.6
Co-authored-by: GPT 5.6 <codex@openai.com>
CopilotAI review requested due to automatic review settings August 17, 2026 04:47

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

@Byron
Byron merged commit d160fb4 into mainAug 17, 2026
54 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Byron