Skip to content

fix: profiles bugs found by Code Scanning #238

Description

@ajianaz

Summary

Code Scanning alerts #69, #72, #73 — bugs in src/engine/profiles.rs and src/config/schema.rs from PR #237.

Bugs

  1. Alert 🔴 Security: TOML injection in save_api_key() #69 — Path::new(name) resolves relative to CWD, not .cora.yaml location. Running cora from a different directory loads wrong profile or fails silently.
  2. Alert 🔒 Security: Auth file permission not validated on read #72 — resolve_profile failure is warn-only. Misspelled or malformed profile in CI silently disables review policy.
  3. Alert 🔒 Security: Git diff arguments not separated with -- #73 — .extend() appends focus_areas without dedup by id. Extending a built-in with redefined area creates duplicate/conflicting prompt instructions.

Fix Plan

Activity

  1. added
    bugSomething isn't working
    v0.5Polish + stability
    on Jun 10, 2026
  2. ajianaz commented on Jun 10, 2026

    @ajianaz
    CollaboratorAuthor

    ✅ Fixed in PR #239. All 3 Code Scanning alerts resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingv0.5Polish + stability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions