Skip to content

fix codeql regex findings and bump mqdb-wasm to 0.3.2 - #4

Merged
fabracht merged 3 commits into
mainfrom
fix/codeql-findings-and-mqdb-bump
Apr 25, 2026
Merged

fabracht merged 3 commits into
mainfrom
fix/codeql-findings-and-mqdb-bump

Conversation

@fabracht

Copy link
Copy Markdown
Contributor

Summary

Addresses both CodeQL findings on main, consolidates the duplicated corruption-detection logic, and updates mqdb-wasm to 0.3.2.

CodeQL fixes

  • js/regex-injection (high, error) in scripts/extract-changelog.mjs:17 — the version arg from CLI was interpolated into a RegExp constructor via a buggy escape function (the character class [.*+?^${}()|[\\]\\\\] is malformed; replacement string \\\\$& over-escapes). Replaced with strict SemVer validation up front + plain string comparison instead of building a regex from untrusted input.
  • js/polynomial-redos (high, warning) in src/memory-store.ts:180 — /transaction.*null|.../i.test(msg) has polynomial complexity on inputs with many transaction prefixes. Replaced with indexOf checks. Same fix applied to the parallel regex in src/persistence-layer.ts:402 (CodeQL didn't flag it because the surface differs slightly, but the pattern is identical).

Refactor

Both MemoryStore.isWasmCorrupted and PersistenceLayer.isDbCorrupted now delegate to a single isCorruptionError(err, extraPatterns) helper exported from internal-wasm-error.ts. Base patterns (arg0 is null, transaction error, unreachable, transaction…null) live in one place; persistence-layer passes its two extras (index out of bounds, database is busy) through the parameter.

Dependency

  • mqdb-wasm 0.3.1 → 0.3.2.

Test plan

  • npm run type-check
  • npm run lint
  • npm run format:check
  • npm test — 27/27 pass
  • npm run build
  • node scripts/extract-changelog.mjs 0.3.0 produces correct output
  • node scripts/extract-changelog.mjs '0.3.0; rm foo' rejects with SemVer error

Commits

  1. fix codeql regex findings and bump mqdb-wasm to 0.3.2 — original fixes + dep bump
  2. consolidate corruption detection into shared helper — extract isCorruptionError to internal-wasm-error.ts

Comment thread scripts/extract-changelog.mjs Fixed
@fabracht
fabracht merged commit 8ee130e into main Apr 25, 2026
4 checks passed
@fabracht
fabracht deleted the fix/codeql-findings-and-mqdb-bump branch April 25, 2026 22:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants