Hacker News
new
top
best
ask
show
job
My minimal, memory-safe Go rsync steers clear of vulnerabilities
(
michael.stapelberg.ch
)
4 points
by
Brajeshwar
4 hours ago
1 comment
3eb7988a1663
2 hours ago
Is there a solid reference resource on handling symlinks? It seems a never ending source of security bugs.
euroderf
an hour ago
The new os.Root is supposed to handle symlinks correctly in a sandbox, but (of course?) the first release had a bug related to symlinks.
d0vs
an hour ago
Agreed. Not a direct answer but this should be interesting:
https://github.com/cyphar/filepath-securejoin