Skip to content

Shamefile

v0.1.7 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

cli code-quality code-review developer-tools linter noqa
+4 more
pre-commit rust static-analysis technical-debt

Affected surfaces

rce_ssrf

Summary

AI summary

Updates Other, main, and deps across a mixed release.

Full changelog

Fixed

  • (main) render shame next snippet from registry, not disk (#80)

Other

  • bump ruff from 0.15.12 to 0.15.13 (#77)
  • bump taiki-e/install-action from 2.77.3 to 2.78.2 (#76)
  • bump release-plz/action from 0.5.128 to 0.5.129 (#75)
  • (deps) bump mako from 1.3.11 to 1.3.12 (#81)
  • bump github/codeql-action from 4.35.4 to 4.35.5 (#78)

Security

  • Fix path traversal in shame next that allowed a crafted
    shamefile.yaml entry to disclose one line of any file readable by the
    current user. The snippet renderer no longer reads from disk; output is
    rendered from the registry's cached content field instead. CWE-22.

Security Fixes

  • CVE‑2025‑XXXXX — Fix path traversal in `shame next` (CWE-22) by rendering snippets from registry's cached content field

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Shamefile

Get notified when new releases ship.

Sign up free

About Shamefile

All releases →

Related context

Beta — feedback welcome: [email protected]