fix(security): reject invalid optional bundle values

This commit is contained in:
2026-07-12 11:53:15 +02:00
parent 449a333365
commit f67d2c97d8
3 changed files with 13 additions and 5 deletions
+2
View File
@@ -55,3 +55,5 @@ outside Compose and mount only the bundle.
- Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather
than being orphaned by `exec`.
- The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.
- Optional key lookup distinguishes an absent key from an invalid value; present malformed
credentials now stop entrypoint startup instead of being silently ignored.