Skip to content

Add PowerShell approval-fatigue facts - #173

Merged
Aaronontheweb merged 2 commits into
devfrom
fix/powershell-approval-fatigue
Sep 14, 2026
Merged

Aaronontheweb merged 2 commits into
devfrom
fix/powershell-approval-fatigue

Conversation

@Aaronontheweb

Copy link
Copy Markdown
Owner

Summary

  • add bounded ordered-list and source-authentic integer-range facts for audited PowerShell arguments
  • add shell-neutral filesystem-tree root and traversal facts with PowerShell 5.1 and PowerShell 7 link behavior
  • preserve fail-closed partial diagnostic syntax for additive consumer hard-deny scans only
  • add sanitized corpus, API snapshots, consumer guidance, and adversarial boundary tests
  • update Microsoft.SourceLink.GitHub to 10.0.400, superseding Bump Microsoft.SourceLink.GitHub from 10.0.301 to 10.0.400 #156

Security boundary

These facts do not grant authority. Dynamic, malformed, ambiguous, drive-relative, non-filesystem, corrupt, and future inputs remain Unknown or unparseable. Diagnostic partial syntax clears all positive authorization facts.

Validation

  • dotnet build -c Release: clean
  • dotnet test -c Release: 3,336 passed
  • header verification: passed
  • corpus PII audit: passed
  • NuGet vulnerability audit: clean
  • public API snapshot: passed
  • Slopwatch changed-file gate: passed

The release version remains 0.3.5. A separate release PR will set 0.4.0-beta.1 after this implementation merges.

@Aaronontheweb
Aaronontheweb merged commit cb84cda into dev Sep 14, 2026
2 checks passed
@Aaronontheweb
Aaronontheweb deleted the fix/powershell-approval-fatigue branch September 14, 2026 11:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant