Skip to content

Harden Vyper standard JSON path handling - #898

Draft
augmentcode[bot] wants to merge 1 commit into
mainfrom
bot/harden-vyper-json-paths
Draft

augmentcode[bot] wants to merge 1 commit into
mainfrom
bot/harden-vyper-json-paths

Conversation

@augmentcode

@augmentcode augmentcode Bot commented Jun 23, 2026

Copy link
Copy Markdown

Problem

  • Standard-json virtual source resolution accepted paths/search paths that could escape the virtual root via .. or absolute paths.

Solution

  • Normalize standard-json paths and reject source, interface, search-path, storage-layout, and load/search contexts outside the virtual root.

Testing

  • SETUPTOOLS_SCM_PRETEND_VERSION=0.4.0 uv run pytest tests/unit/cli/vyper_json/test_get_inputs.py tests/unit/compiler/test_input_bundle.py tests/unit/cli/vyper_json/test_compile_json.py tests/unit/cli/vyper_json/test_parse_args_vyperjson.py
  • SETUPTOOLS_SCM_PRETEND_VERSION=0.4.0 uv run black --check vyper/cli/vyper_json.py vyper/compiler/input_bundle.py tests/unit/cli/vyper_json/test_get_inputs.py tests/unit/compiler/test_input_bundle.py

Misc

  • Session metadata did not include github_username, so attribution fell back to bot settings.

Pull Request opened by Augment Code | View session

@augmentcode

augmentcode Bot commented Jun 23, 2026

Copy link
Copy Markdown
Author

PR Author Agent⚡

👋 I've got this PR.

I'll handle review feedback, CI failures, and merge conflicts, and ping you the moment it's ready for review. Drop a comment anytime.

Marking it ready and picking reviewers are your call — I'll leave both alone.

@augmentcode

augmentcode Bot commented Jun 30, 2026

Copy link
Copy Markdown
Author

PR Author Agent⚡

This PR appears to be inactive. The agent will stop monitoring until a new comment is posted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants