Skip to content

fix: sanitize GCS blob names to prevent path traversal in skill loading#5281

Open
cherry-bisht wants to merge 14 commits into
google:mainfrom
cherry-bisht:main
Open

fix: sanitize GCS blob names to prevent path traversal in skill loading#5281
cherry-bisht wants to merge 14 commits into
google:mainfrom
cherry-bisht:main

test: add security tests for path traversal fix (VRP #499557362)

d340122
Select commit
Loading
Failed to load commit list.
Google CLA / cla/google succeeded May 8, 2026 in 27s

✅ All contributors are covered under a CLA with Google

See https://cla.developers.google.com/ for more info about Google's Contributor License Agreement (CLA).

ℹ️ Googlers: Go here to view more details and manage scans for this pull request.

Details

The following contributors were found for this pull request:

025f834 Author: @cherry-bisht <adit********dev​@gmail.com>
0e0f6d6 Author: @rohityan <rya******la​@google.com>
d39dfdd Author: @adityabisht-lab <bi****ji​@outlook.com>
d340122 Author: <djc*****wi​@gmail.com>

(Only the first commit for a unique contributor is listed.)