Sourced from github.com/cyphar/filepath-securejoin's releases.
v0.2.4
This release fixes a potential security issue in filepath-securejoin when used on Windows (GHSA-6xv5-86q9-7xr8, which could be used to generate paths outside of the provided rootfs in certain cases), as well as improving the overall behaviour of filepath-securejoin when dealing with Windows paths that contain volume names. Thanks to Paulo Gomes for discovering and fixing these issues.
In addition, we've switched (at long last) to GitHub Actions and have continuous integration testing on Linux, MacOS, and Windows.
Thanks to the following contributors for making this release possible:
- Aleksa Sarai cyphar@cyphar.com
- Paulo Gomes pjbgf@linux.com
Signed-off-by: Aleksa Sarai cyphar@cyphar.com