aws / aws/amazon-q-developer-cli

Using `q issue` injects the full PATH in the GitHub issue (Environment section)

Aperta
#895 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Rust
Stelle
2k
Fork
439
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Checks

- [x] I have searched [github.com/aws/amazon-q-developer-cli/issues](https://github.com/aws/amazon-q-developer-cli/issues?q=) and there are no duplicates of my issue
- [x] I have run `q doctor` in the affected terminal session
- [x] I have run `q restart` and replicated the issue again

### Operating system

macOS 15.3.1 (24D70)

### Expected behaviour

This current behavior seems somewhat invasive in terms of privacy/security because the PATH contains several installed software/tools. This information could be misused by attackers.

### Actual behaviour

The "Environment" section on the Github Create issue page shows harmless details at the top, but hidden below is the full PATH.

### Steps to reproduce

_No response_

### Environment

```yaml

```

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by reproducing the behavior with `q issue` in the affected terminal session and inspect the generated GitHub issue's Environment section. Trace where that section is assembled, then verify that the full PATH is no longer included while the remaining environment details still appear as expected.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
rust
Ambito
cli, security
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Da chiarire
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.