From e1f169a378b163aefa0259e64490e40d89964f4b Mon Sep 17 00:00:00 2001 From: sim Date: Sat, 12 Sep 2026 10:41:11 -0400 Subject: [PATCH] chore(#4652): backfill changeset PR number to 4666 Co-Authored-By: Claude Opus 5 --- .changeset/sharp-tigers-sing.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.changeset/sharp-tigers-sing.md b/.changeset/sharp-tigers-sing.md index 6e1ad8f45..840c17164 100644 --- a/.changeset/sharp-tigers-sing.md +++ b/.changeset/sharp-tigers-sing.md @@ -1,5 +1,5 @@ --- type: Security -pr: 0 +pr: 4666 --- **Path containment at every boundary that takes a directory or filename from the command line** — `todo complete` followed a traversal name outside the todos root and moved the file it found there, `check predicate --phase-dir` let a blocking gate return a passing verdict on evidence from a directory the caller chose, and the shared `resolvePath` helper — used by `check decision-coverage-plan` and `check gap-analysis.plan-post` — accepted a phase directory outside the project. All boundaries now validate against their managed root and reject with a usage error before touching the filesystem. (#4327, #4354)