Skip to content

Server protects yaml as well as yml#2182

Merged
lissy93 merged 1 commit into
masterfrom
fix/extend-yml-protection-to-yaml-too
Jun 4, 2026
Merged

Server protects yaml as well as yml#2182
lissy93 merged 1 commit into
masterfrom
fix/extend-yml-protection-to-yaml-too

Conversation

@lissy93
Copy link
Copy Markdown
Owner

@lissy93 lissy93 commented Jun 4, 2026

Category

Bugfix / Security

Overview

There was a bug, whereby: if you use OIDC for auth, and update your config locations via custom env vars to use .yaml instead of .yml then auth will not work.

Note that while this was opened as a security advisory, and I will publish the advisory or transparency and to trigger updates, this issue doesn't actually have any way to exploit, and so is a no-op.

Issue Number

Thanks @huslayer826 for reporting this, in GHSA-7v4p-jf7g-wpg7!

@lissy93 lissy93 merged commit fa78ca7 into master Jun 4, 2026
11 checks passed
@lissy93 lissy93 deleted the fix/extend-yml-protection-to-yaml-too branch June 4, 2026 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant