- Replace .golangci.yml with the canonical strict config (all linters
enabled except the standard disable list; lll 88, funlen 80/50,
cyclop 15, dupl 100; test files now linted)
- Pin the Dockerfile lint stage to golangci/golangci-lint:v2.12.2 by
tag and digest (Debian-based)
- Fix all ~1550 findings surfaced by the new config: line wrapping,
wsl_v5/nlreturn blank lines, noinlineerr splits, err113 sentinel
errors, perfsprint/modernize rewrites, goconst constants, thelper,
testifylint, noctx CommandContext, testpackage conversions,
t.Parallel() where safe, and complexity/dupl helper extraction
- Record the change and follow-up items in TODO.md
- isValidSecretName() now rejects names with '..' path components (e.g. foo/../bar)
- GetSecretObject() now calls isValidSecretName() before building paths
- Added test cases for mid-path traversal patterns
Add isValidSecretName() check at the top of GetSecretVersion(), matching
the existing validation in AddSecret(). Without this, crafted secret names
containing path traversal sequences (e.g. '../../../etc/passwd') could be
used to read files outside the vault directory.
Add regression tests for both GetSecretVersion and GetSecret.
Closes#13