The GitHub Actions job "gradle in /. - Update #1351358346" on 
ofbiz-framework.git/release24.09 has failed.
Run started by GitHub user dependabot[bot] (triggered by dependabot[bot]).

Head commit for run:
d094e5a4115c7f056096a3e1d6583a001aef28cc / Jacopo Cappellato 
<[email protected]>
Fixed: Improve file path validation to work with mounted directories

File.getCanonicalPath() resolves all symlinks in a path. OS-level mount points 
(Docker bind mounts, EFS) appear as symlinks. When a subdirectory like runtime/ 
is mounted, a file's canonical path resolves to the mount target (e.g. 
/mnt/efs/data/file.pdf), which no longer shares a prefix with the canonical 
path of ofbiz.home (/opt/ofbiz)

(cherry picked from commit b3eadf1cff2e3431e57c1f2002333fb22e0a458a)

Report URL: https://github.com/apache/ofbiz-framework/actions/runs/25438964700

With regards,
GitHub Actions via GitBox

Reply via email to