* use security_fix category in changelogs for CVEs * these fragments do not say CVE but are security fixes Co-authored-by: Alicia Cozine <acozine@users.noreply.github.com>
* Actually inspect the paths and prevent escape * Add integration tests * Generate zip files for use in integration test * Adjust error message