You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 3564cb2
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/security.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,6 +22,7 @@ On upgrade from older databases, existing plaintext secrets in SQLite are **migr
22
22
23
23
Automated tests use an **in-memory** secrets backend (see `test/flutter_test_config.dart`) so CI does not require a desktop keyring.
24
24
25
+
25
26
## Archive install limits (extensions and updates)
26
27
27
28
Marketplace downloads, local extension sideload (`.zip` / `.qext`), and in-app updater extraction use `SafeZipExtractor` (`lib/core/security/safe_zip_extractor.dart`) with shared default limits:
@@ -35,3 +36,4 @@ Marketplace downloads, local extension sideload (`.zip` / `.qext`), and in-app u
35
36
| Max compression ratio (uncompressed ÷ compressed) | 100:1 |
36
37
37
38
Archives exceeding these bounds fail closed before files are written to disk. Path traversal checks remain in `archive_path_guard.dart`.
0 commit comments