Skip to content

fix: clear CodeQL findings before main promotion - #68

Merged
salim4n merged 1 commit into
devfrom
fix/codeql-main-promotion
Aug 24, 2026
Merged

fix: clear CodeQL findings before main promotion#68
salim4n merged 1 commit into
devfrom
fix/codeql-main-promotion

Conversation

@salim4n

@salim4n salim4n commented Aug 24, 2026

Copy link
Copy Markdown
Member

Summary\n- constrain internal API requests to the configured HTTP(S) origin\n- replace regex HTML filtering with DOM-based sanitization and single-pass text decoding\n- harden Markdown table escaping and comment removal\n- add focused regression tests for SSRF and hostile HTML\n\n## Validation\n- bun run check (594 Bun tests, 43 crawler tests, architecture and production builds)\n- 15 focused security regression tests\n- git diff --check\n- changed-code secret scan\n\nCloses the seven new CodeQL findings blocking #67.

@salim4n
salim4n merged commit 4e5ed58 into dev Aug 24, 2026
1 check passed
@salim4n
salim4n deleted the fix/codeql-main-promotion branch August 24, 2026 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant