fix(security): reject invalid optional bundle values
This commit is contained in:
@@ -55,3 +55,5 @@ outside Compose and mount only the bundle.
|
||||
- Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather
|
||||
than being orphaned by `exec`.
|
||||
- The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.
|
||||
- Optional key lookup distinguishes an absent key from an invalid value; present malformed
|
||||
credentials now stop entrypoint startup instead of being silently ignored.
|
||||
|
||||
Reference in New Issue
Block a user