SyntaxHighlight shells out to pygments, which should be restricted with firejail.
Description
Description
Details
Details
Project | Branch | Lines +/- | Subject | |
---|---|---|---|---|
mediawiki/extensions/SyntaxHighlight_GeSHi | master | +7 -2 | Use shell restrictions to contain pygments |
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Declined | None | T172584 Securing external binaries run by MediaWiki | |||
Resolved | Legoktm | T182468 Restrict pygments with firejail | |||
Resolved | Legoktm | T182467 Use Shell\Command in SyntaxHighlight instead of symfony/process | |||
Resolved | Tgr | T182463 Shell\Command should support providing standard input |
Event Timeline
Comment Actions
Change 396477 had a related patch set uploaded (by Legoktm; owner: Legoktm):
[mediawiki/extensions/SyntaxHighlight_GeSHi@master] Use shell restrictions to contain pygments
Comment Actions
Change 396477 merged by jenkins-bot:
[mediawiki/extensions/SyntaxHighlight_GeSHi@master] Use shell restrictions to contain pygments