Skip to content

esbuildsandbox, one function against one leak - #7

Merged
tannevaled merged 1 commit into
mainfrom
the-sandbox-leak-nobody-advertised
Sep 26, 2026
Merged

tannevaled merged 1 commit into
mainfrom
the-sandbox-leak-nobody-advertised

Conversation

@tannevaled

Copy link
Copy Markdown
Contributor

Three modules, two cards.

The missing one is the security fix, and the card spends its space on the mechanism rather than the API — the API is one call. A plugin that intercepts every import still leaks, because the bundler expands a glob dynamic import by walking ResolveDir on the real filesystem, following symlinks, with OnResolve/OnLoad never seeing it.

Built with the version this repository pins (Hugo 0.135.0). Companion: go-webengine/.github#17.

🤖 Generated with Claude Code

Three modules, two cards. The missing one is the security fix, and the card
spends its space on the mechanism rather than the API, because the API is one
call: a plugin that intercepts every import still leaks, since the bundler
expands a glob dynamic import by walking ResolveDir on the real filesystem.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@tannevaled
tannevaled merged commit e61e758 into main Sep 26, 2026
3 checks passed
@tannevaled
tannevaled deleted the the-sandbox-leak-nobody-advertised branch September 26, 2026 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant