mirror of
https://github.com/guillaumemeyer/watermarks-remover.git
synced 2026-08-22 13:11:57 +02:00
Security hardening from deep assessment: - Writes: atomic temp+rename via safe_write_bytes/text (no symlink following, no partial in-place loss); backup_path for --in-place; umask-default modes; symlink destinations refused. - rewrite_text: refuse redirects (no Authorization/key re-send to unvalidated hosts), default-deny loopback allowlist with explicit --allow-remote / WATERMARKS_REWRITE_ALLOW_REMOTE opt-in, http(s)-only schemes, --api-key argv flag removed (env-only). - CI: SHA-pin actions (checkout v7.0.1, setup-python v7.0.0, codeql), permissions: contents: read, pinned requirements-dev.txt, pip-audit step; new CodeQL workflow. - Scorer deps: bump Pillow 10.4.0 -> 12.3.0 (24 known CVEs); pip pinned in Dockerfile and setup_synthid.sh; Docker runs as unprivileged user. - Resource caps: MAX_INPUT_BYTES 1GiB -> 256MiB, 64MiB stdin cap, zip budget 512MiB -> 128MiB, RLIMIT_AS/FSIZE on child processes. - Tests: 18 new security regression tests (60 total, all passing).
5 lines
159 B
Plaintext
5 lines
159 B
Plaintext
# Dev/test dependencies for CI — exact pins (no drift).
|
|
# Dependabot can bump these; keep them in sync with the local .venv.
|
|
pytest==9.1.1
|
|
pip-audit==2.10.1
|