You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 0ea71c0
Browse filesBrowse the repository at this point in the historyBrowse files
Reject blame options that read arbitrary files and inspect tag path and reference positional arguments after resolving the legacy ref alias. This closes GHSA-5xxx-qhh7-9287 and GHSA-3wxw-xv34-2frg without changing the explicit allow_unsafe_options escape hatch.
Regression tests cover long, short, and clustered blame options, incremental blame, tag path/reference positionals, the ref keyword alias, and preservation of diff pickaxe behavior.
Git baseline: cf5497b14c; git-blame documents its file-input options and tests --contents in t/annotate-tests.sh, while git-tag documents --file.
Validation:
- focused pytest regressions (4 passed)
- test_repo.py and test_refs.py (108 passed, 2 skipped, 5 unrelated environment/history failures)
- ruff check on changed files
- git diff --check
0 commit comments