Block a user
[Security] Review dynamic SQL text findings and add safe identifier helpers
Codex State: done
Summary
- Added a safe table-identifier guard for core migration schema reconciliation helpers before quoting identifiers into literal SQL.
- Guarded the matching dev…
[Security] Centralize outbound URL policy for core fetches and health checks
[Security] Centralize outbound URL policy for core fetches and health checks
Codex State: done
Summary
- Strengthened core HTTP URL checks to require absolute HTTP(S), a hostname, and no embedded credentials.
- Applied the guard to module package catalog fetches,…
[Security] Harden module installer shell command hooks
[Security] Harden module installer shell command hooks
Codex State: done
Summary
- Replaced module installer restart and database hook
shell=Trueexecution with argv execution viashlex.split. - Shell operators, redirects, substitutions,…
[Security] Harden meta release/Gitea tooling command and URL trust boundaries
[Security] Harden meta release/Gitea tooling command and URL trust boundaries
Codex State: done
Summary
- Replaced release-doctor
shell=Trueexecution with argv execution for suggested commands. - Added explicit argv definitions for release tagging, migration…