Allow command allowlists in company restricted mode
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Facilidade para iniciantes
- 35/100
- Tipo de issue
- Funcionalidade
- Clareza
- Razoavelmente clara
- Status de atividade
- Ativa
- Stack de tecnologia
- git, shell
- Domínio
- authorization, devtools, security
Direção de pesquisa
A issue não nomeia arquivos, testes ou pontos de entrada concretos. Comece localizando o caminho de autorização existente para restricted-mode e allow-all, o fluxo de aprovação, o tratamento da execução de comandos, a exibição de decisões na UI e o tratamento do log de auditoria; o trabalho estará concluído quando uma allowlist gerenciada centralmente e resistente a injeção funcionar no escopo da empresa sem alterar o comportamento quando ela estiver ausente.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Summary
Add support for administrators to define a whitelist of shell commands that the agent may run when company restricted mode is enabled and allow-all is disabled.
Problem
Restricted mode blocks commands by default, but teams may still need a small set of safe, routine commands for development workflows. Currently, enabling these workflows may require relaxing the broader allow-all restriction, weakening the intended security boundary.
Proposed solution
Provide an administrator-managed command allowlist for company restricted mode:
- Commands matching the allowlist are permitted without an additional approval prompt.
- Non-matching commands remain blocked or follow the existing approval flow.
- The allowlist can be managed centrally at the company, organization, repository, or user scope.
- Matching supports exact commands and explicitly constrained arguments, rather than unrestricted substring matching.
- The UI indicates when a command was allowed by an administrator-defined rule.
- Audit logs record the command, matched rule, user, repository, and timestamp.
Example allowed commands could include:
git status
git diff --check
swiftlint
npm test
Security considerations
The implementation must prevent bypasses through shell operators, command substitution, pipelines, redirects, aliases, path traversal, and argument injection. Rules should be validated before activation, and administrators should be able to review, update, and disable them.
Acceptance criteria
- Administrators can configure and manage a company-level command allowlist.
- The allowlist works while restricted mode is enabled and
allow-allis disabled. - Non-matching commands retain the existing restriction behavior.
- Matching is deterministic, documented, and resistant to shell-injection bypasses.
- Allowed-command decisions are visible to users and captured in audit logs.
- Existing behavior is unchanged when no allowlist is configured.
- Linguagem predominante
- Sem dados de linguagem
- Estrelas
- 2.2k
- Forks
- 176
- Métricas de merge de PRs
- Nenhum PR com merge em 30d
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/app
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 62/100
Issues semelhantes
-
Executable-extension and MIME blocklist is case-sensitive; .EXE and mixed-case variants bypass itAbertabug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
awslabs/visual-asset-management-system#412 ·
Mantenedores costumam responder em até 1 dia
-
[BUG] 订单:会员凭订单号即可取消其他会员的待付款订单(取消接口不校验订单归属)Talvez já em andamento @dadiyang assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
macrozheng/mall#1016 ·
-
[Bug] Four credential types still print their secrets in toStringTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
apache/rocketmq-dashboard#6091 ·
Mantenedores costumam responder em até 4 dias
-
area:auth bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 62/100
ArchiveLabs/lenny#242 ·
Mantenedores costumam responder em até 1 dia