fix(security): resolve chrome sandbox escapes and prompt injections - #138
Open
Youcef3939 wants to merge 1 commit into
Open
fix(security): resolve chrome sandbox escapes and prompt injections#138Youcef3939 wants to merge 1 commit into
Youcef3939 wants to merge 1 commit into
Conversation
|
@Youcef3939 is attempting to deploy a commit to the andylizf's projects Team on Vercel. A member of the Team first needs to authorize it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
this pull request refactors how chrome sandboxing arguments are handled throughout the codebase. instead of unconditionally passing
--no-sandbox, a new centralized function determines when sandboxing should be disabled, improving security and flexibility. additionally, documentation has been updated for clarity and safetysandbox argument handling
sandbox_args()function inchrome.pythat returns Chrome sandbox arguments, only adding--no-sandboxif running as root on Linux or if thePIXELSHOT_NO_SANDBOXenvironment variable is set. It also logs a warning when running as rootcdp.py,fast_cdp.py,cdp_overlap.py,cdp_pipelined_dc.py,cdp_pipelined_tabs.py,connection.py,render_ondemand.py, andscreenshot.py) to usesandbox_args()instead of hardcoding--no-sandbox. [1] [2] [3] [4] [5] [6] [7] [8]documentation and safety
SKILL.mdandscreenshot.mdto clarify usage, add safety warnings about untrusted screenshot payloads, and improve cropping instructions with a more robust pillow script. [1] [2] [3]code organization
sandbox_argsin all relevant modules for consistency and maintainability. [1] [2] [3] [4] [5] [6] [7] [8]also part of the issue #135