Skip to content

quick wins security dead code - #5

Merged
ShanedixonGit merged 3 commits into
mainfrom
quick-wins-security-dead-code
Sep 26, 2026
Merged

ShanedixonGit merged 3 commits into
mainfrom
quick-wins-security-dead-code

Conversation

@ShanedixonGit

Copy link
Copy Markdown
Owner
  • Refuse to write a report through a symlink, so a shared folder cannot redirect it
  • Stop leaving the GitHub token in CI checkouts, since no job pushes
  • Remove functions, constants and a parameter that nothing used

… redirect it

A symlink planted at audit_*.json, audit_*.html or remediation.md was
followed, sending the report to wherever it pointed. Reports are now
opened with O_NOFOLLOW and set to 0600 on the open descriptor before
anything is written.
search_roots, THERMAL_KEYS, _yes_no and _simple's privileged_hint had no
callers, and shell.run had an except branch identical to the catch-all
below it. Audit output is unchanged.
@ShanedixonGit
ShanedixonGit merged commit 807525f into main Sep 26, 2026
7 checks passed
@ShanedixonGit
ShanedixonGit deleted the quick-wins-security-dead-code branch September 26, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant