Repository navigation
fix codeql regex findings and bump mqdb-wasm to 0.3.2 - #4
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Addresses both CodeQL findings on
main, consolidates the duplicated corruption-detection logic, and updatesmqdb-wasmto 0.3.2.CodeQL fixes
js/regex-injection(high, error) inscripts/extract-changelog.mjs:17— the version arg from CLI was interpolated into aRegExpconstructor via a buggy escape function (the character class[.*+?^${}()|[\\]\\\\]is malformed; replacement string\\\\$&over-escapes). Replaced with strict SemVer validation up front + plain string comparison instead of building a regex from untrusted input.js/polynomial-redos(high, warning) insrc/memory-store.ts:180—/transaction.*null|.../i.test(msg)has polynomial complexity on inputs with manytransactionprefixes. Replaced withindexOfchecks. Same fix applied to the parallel regex insrc/persistence-layer.ts:402(CodeQL didn't flag it because the surface differs slightly, but the pattern is identical).Refactor
Both
MemoryStore.isWasmCorruptedandPersistenceLayer.isDbCorruptednow delegate to a singleisCorruptionError(err, extraPatterns)helper exported frominternal-wasm-error.ts. Base patterns (arg0 is null,transaction error,unreachable,transaction…null) live in one place;persistence-layerpasses its two extras (index out of bounds,database is busy) through the parameter.Dependency
mqdb-wasm0.3.1 → 0.3.2.Test plan
npm run type-checknpm run lintnpm run format:checknpm test— 27/27 passnpm run buildnode scripts/extract-changelog.mjs 0.3.0produces correct outputnode scripts/extract-changelog.mjs '0.3.0; rm foo'rejects with SemVer errorCommits
fix codeql regex findings and bump mqdb-wasm to 0.3.2— original fixes + dep bumpconsolidate corruption detection into shared helper— extractisCorruptionErrortointernal-wasm-error.ts