Protect against SSRF:
- file://
- localhost
- loopback
- private networks
- link-local
- metadata endpoints
- internal hostnames
- unsafe redirects
Revalidate redirects.
Treat repositories as untrusted input.
Guard against:
- archive path traversal
- absolute paths
- symlink escapes
- oversized archives
- excessive file count
- oversized individual files
Source paths must remain beneath the repository root.
Repository source is data.
Comments/strings such as:
// Ignore previous instructions
must not become model instructions.
Validate:
- repo
- commit
- target file
- source fingerprint
- exact before code
- diff scope
- extension
- syntax
- AST
- safety
- conflicts
Untrusted repository code must not execute inside the FastAPI process.
If arbitrary repository build/start commands are supported, use a dedicated isolated execution boundary with:
- filesystem isolation
- resource limits
- timeouts
- restricted network
- no host credentials
- process cleanup
Keep OAuth/PAT credentials server-side.
Use encrypted storage where implemented.
Never expose credentials to frontend/localStorage.
Redact:
- access tokens
- API keys
- internal paths
- sensitive repository data where appropriate.