- Sort signed headers and manifest keys with an explicit byte comparator.
SigV4 needs byte order; localeCompare (what Sonar suggested) is locale-aware
and would order some headers differently from the server, breaking signing.
- Copy before sorting the manifest keys instead of mutating in place.
- Sanitise remote-derived strings before logging them: release tags, asset names
and error bodies come from outside this script, and a newline in one of them
can forge log lines in the CI output.
Re-verified after the change: signed PUT + HEAD round-trip succeeds with valid
credentials and still fails with SignatureDoesNotMatch on a bad secret.