install-core.ps1: - Add Test-SecureDirectory and New-SecureDirectory to mitigate TOCTOU races - Add Test-GitTagSignature for GPG verification of git tags - Make ACL failures fatal for temp directories with retry logic - Use precise PATH matching instead of substring contains - Add unique GUID suffix to temp file names - Document security controls and known limitations in header setup.bat: - Validate LOCALAPPDATA is within USERPROFILE - Reject paths with invalid shell characters - Add symlink detection for install directory - Use delayed expansion variables for path safety Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| install-core.ps1 | ||
| install-core.sh | ||
| install-deps.ps1 | ||
| install-deps.sh | ||