mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-23 00:41:40 +00:00
Address two related Veria comments on the claude_code_compat_pr_gate job: 1. (line ~2320) The PR-gate version resolver is PR-controlled Python that runs in the same CircleCI job as the provider secrets injected later into the proxy container. A malicious PR could modify tests/claude_code/pr_gate_version_resolver.py to read ANTHROPIC_API_KEY / AWS_* / VERTEXAI_* / AZURE_FOUNDRY_* / GITHUB_TOKEN out of os.environ and exfiltrate them over the resolver's outbound npm registry HTTPS call. 2. (line ~2335) `npm install -g @anthropic-ai/claude-code` runs the package's `postinstall: node install.cjs` script (verified against the npm registry metadata for @anthropic-ai/claude-code), which executes arbitrary code from npm with the full job env. `claude --version` on the next line also runs package code. A compromised package release (or transitive registry hijack) could exfiltrate the same provider credentials. --ignore-scripts is not viable: the postinstall is the step that fetches the platform binary, so skipping it would leave the install unusable. Mitigation: - Wrap both invocations in `env -i` with a minimal allowlist (PATH / HOME / USER / TERM / LANG / LC_ALL / TMPDIR — plus NVM_DIR + CLAUDE_CODE_VERSION on the npm step). BASH_ENV is intentionally NOT passed through so the scrubbed subshell can't re-source prior steps' exports. - Pin the scrub with two new unit tests in test_circleci_pr_gate_wiring.py so a future YAML refactor cannot silently drop the env -i wrapper and revert the mitigation. The tests verify both that `env -i` is present in each step and that it precedes the actual at-risk invocation in the command body. Verified locally that `env -i PATH=$PATH HOME=$HOME ... uv run --no-sync python -m tests.claude_code.pr_gate_version_resolver` still resolves and prints a CLI version successfully. Co-authored-by: Cursor Agent <cursoragent@cursor.com> |
||
|---|---|---|
| .. | ||
| _builder_unit_tests | ||
| _driver_unit_tests | ||
| _pr_gate_unit_tests | ||
| _publisher_unit_tests | ||
| basic_messaging_non_streaming | ||
| basic_messaging_streaming | ||
| count_tokens | ||
| cron_vm | ||
| long_context_1m | ||
| pdf_input | ||
| prompt_caching_1h | ||
| prompt_caching_5m | ||
| structured_outputs | ||
| thinking | ||
| thinking_with_tool_use | ||
| tool_search | ||
| tool_use | ||
| tool_use_streaming | ||
| vision | ||
| web_search | ||
| __init__.py | ||
| _basic_messaging.py | ||
| cli_driver.py | ||
| conftest.py | ||
| http_probe.py | ||
| manifest.yaml | ||
| matrix_builder.py | ||
| pr_gate_version_resolver.py | ||
| rate_limiter.py | ||
| run_compat.sh | ||
| sample_compatibility-matrix.json | ||
| test_config.yaml | ||