diff --git a/doc/go1.15.html b/doc/go1.15.html index d17888732b..0c345f22e2 100644 --- a/doc/go1.15.html +++ b/doc/go1.15.html @@ -395,7 +395,11 @@ TODO
- TODO: https://golang.org/cl/212597: reject path separators in TempDir, TempFile pattern
+ TempDir and
+ TempFile
+ now reject patterns that contain path separators.
+ That is, calls such as ioutil.TempFile("/tmp", "../base*") will no longer succeed.
+ This prevents unintended directory traversal.