Closed gibson042 closed 6 years ago
The link no longer works.
Well, I suppose the consequences of submitting commit hashes containing single-quote characters (or worse) without this change are obvious.
Yeah, that's true.
This may only bite in combination with CLA checker bugs, right? User-provided input was already sanitized, repo/owner/sha are first used to generate $data
and nothing would be found for rogue fake ones.
I believe that's correct.
OK, it shouldn't be extremely critical then. LGTM.
A year and a half with no injection attacks, but I updated it anyway. :upside_down_face:
cf. http://contribute.jquery.org/CLA/status/?owner=jquery&repo=jquery&sha=e217c1949f625c4c4ae7b9e93943310c73ef55ac