浏览代码

chore(installer): only serve installer in / and /install.sh

This avoids false positive detections on other bruteforced paths,
such as .zsh_history or others, which eventually result in
automated false vulnerability submissions.
Marc Cornellà 1 月之前
父节点
当前提交
4ada154190
共有 1 个文件被更改,包括 2 次插入2 次删除
  1. 2 2
      .github/workflows/installer/vercel.json

+ 2 - 2
.github/workflows/installer/vercel.json

@@ -1,7 +1,7 @@
 {
   "headers": [
     {
-      "source": "/((?!favicon.ico).*)",
+      "source": "/(|install.sh)",
       "headers": [
         {
           "key": "Content-Type",
@@ -16,7 +16,7 @@
   ],
   "rewrites": [
     {
-      "source": "/((?!favicon.ico|install.sh).*)",
+      "source": "/",
       "destination": "/install.sh"
     }
   ]