dev #2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "dev"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
- release-iso.yml's "Build bread-theme from source" step grepped bos-settings/Cargo.toml for the bread-theme tag pin, but bos-settings was split out into its own repo (git.breadway.dev/Breadway/bos-settings) -- that path no longer exists in this checkout, so the grep would fail (or silently find nothing). Now fetches bos-settings' Cargo.toml directly from its own repo (dev branch, the one its own CI actually publishes the bos-settings pacman package from) via the Forgejo raw-file endpoint. - calamares.yml cloned the repo's default branch instead of the branch/tag that actually triggered the run -- bibata.yml, powerlevel10k.yml, and yay-bin.yml (the other in-house-PKGBUILD workflows in this same family) all correctly clone --branch "${GITHUB_REF_NAME}". Brought calamares.yml in line with them. - breadhelp-tour.lua interpolated an untrusted, client-controlled Wayland window class / layer-shell namespace directly into a bread.exec shell command string -- a session-level shell injection vector (verified exploitable with a crafted window class before this fix, e.g. "evil; touch ~/pwned #"). bread.exec only accepts a single shell string (always run via `sh -lc`, per breadd/src/lua/mod.rs) -- there's no array-exec form to bypass the shell with -- so the fix is a proper POSIX shell_quote() helper wrapping every interpolated value in single quotes before it reaches bread.exec.