fix: guard against short paths in changelog GitHub URL redirect - #9688
Conversation
Signed-off-by: Arunesh Dwivedi <arunesh.dwivedi@example.com>
|
Hi @AruneshDwivedi, |
|
@olblak good question it's a real panic, not a theoretical one. |
redirectToGitHubRawContent splits the changelog URL path on "/" and reads index 3 without checking the length, so a github.com changelog URL with fewer than four path segments panics with index out of range. Since the URL comes from the org.opencontainers.image.changelog image annotation, a short value like https://github.com/CHANGELOG.md crashes the run.
Split once, check the slice has more than three elements before touching index 3, and leave short paths unchanged.