- modules_mgmt.rs: reject module names containing path separators, `..`,
or absolute paths before joining onto modules_dir (install_from_local,
remove_module, read_module_manifest); adds canonicalized containment
check as defense in depth. Manifest-supplied names and CLI args were
previously joined unsanitized, allowing path traversal on install/remove.
- breadd/src/lua/mod.rs: bread.exec now runs via `sh -c` instead of
`sh -lc`; no documented reason was found for login-shell semantics.
- Unify the two independently hand-written glob matchers (subscription
dispatch in breadd/src/core/subscriptions.rs vs. the CLI --filter path
in breadd/src/ipc/mod.rs) into one implementation in
bread-shared/src/glob.rs, used by both call sites.
- Remove the dead bread-sync/ tree (already excluded from the workspace
and fully unreferenced) and its stale PKGBUILD deps (libgit2, git
optdepend) and packaging docs mention.
- Correct the version-number transposition bug ("6.2.0" instead of
"0.6.2"/"0.6.6") across bread-shared, breadd, and bread-cli Cargo.toml,
and fix PKGBUILD's stale pkgver, so Cargo.toml/doctor/PKGBUILD all agree
with the latest git tag (v0.6.6).
28 lines
496 B
TOML
28 lines
496 B
TOML
[package]
|
|
name = "bread-cli"
|
|
version = "0.6.6"
|
|
edition = "2021"
|
|
|
|
[[bin]]
|
|
name = "bread"
|
|
path = "src/main.rs"
|
|
|
|
[lib]
|
|
name = "bread_cli"
|
|
path = "src/lib.rs"
|
|
|
|
[dependencies]
|
|
bread-shared = { path = "../bread-shared" }
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
tokio.workspace = true
|
|
anyhow.workspace = true
|
|
chrono.workspace = true
|
|
dirs.workspace = true
|
|
clap = { version = "4.5", features = ["derive"] }
|
|
notify = "6.1"
|
|
libc = "0.2"
|
|
toml = "0.8"
|
|
|
|
[dev-dependencies]
|
|
tempfile.workspace = true
|