aws / aws/amazon-q-developer-cli

Using `q issue` injects the full PATH in the GitHub issue (Environment section)

Offen
#895 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Rust
Sterne
2k
Forks
439
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

### Checks

- [x] I have searched [github.com/aws/amazon-q-developer-cli/issues](https://github.com/aws/amazon-q-developer-cli/issues?q=) and there are no duplicates of my issue
- [x] I have run `q doctor` in the affected terminal session
- [x] I have run `q restart` and replicated the issue again

### Operating system

macOS 15.3.1 (24D70)

### Expected behaviour

This current behavior seems somewhat invasive in terms of privacy/security because the PATH contains several installed software/tools. This information could be misused by attackers.

### Actual behaviour

The "Environment" section on the Github Create issue page shows harmless details at the top, but hidden below is the full PATH.

### Steps to reproduce

_No response_

### Environment

```yaml

```

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by reproducing the behavior with `q issue` in the affected terminal session and inspect the generated GitHub issue's Environment section. Trace where that section is assembled, then verify that the full PATH is no longer included while the remaining environment details still appear as expected.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rust
Bereich
cli, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.